CVE-2025-32896 is a critical vulnerability affecting Apache SeaTunnel versions up to and including 2.3.10. It allows unauthorized users to perform arbitrary file read and deserialization attacks by submitting a job via the restful API-v1, specifically through the `/hazelcast/rest/maps/submit-job` endpoint. Attackers can leverage extra parameters in a MySQL URL to trigger these attacks. Rated with a CVSS score of 6.5 (Medium), this vulnerability has a network attack vector and low attack complexity, requiring no user interaction. A successful exploit could lead to high confidentiality impact, allowing attackers to read sensitive files, though integrity and availability are not directly impacted. The CWE-306 classification indicates missing authentication for a critical function. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting low public awareness at this time. Users are advised to upgrade to version 2.3.11 and enable restful API-v2 with HTTPS two-way authentication to mitigate the risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.3.1, < 2.3.11CPE matchmatch criteria | cpe:2.3:a:apache:seatunnel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.