cbcvebase.
CVE-2025-32896
published 2025-06-19

CVE-2025-32896: # Summary Unauthorized users can perform Arbitrary File Read and Deserialization attack by submit job using restful api-v1. # Details Unauthorized users can…

PriorityP341medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
1.06%
60.7th percentile
# Summary

Unauthorized users can perform Arbitrary File Read and Deserialization
attack by submit job using restful api-v1.

# Details
Unauthorized users can access `/hazelcast/rest/maps/submit-job` to submit
job.
An attacker can set extra params in mysql url to perform Arbitrary File
Read and Deserialization attack.

This issue affects Apache SeaTunnel: <=2.3.10

# Fixed

Users are recommended to upgrade to version 2.3.11, and enable restful api-v2 & open https two-way authentication , which fixes the issue.

Affected

2 ranges
VendorProductVersion rangeFixed in
apacheseatunnel>= 2.3.1 < 2.3.112.3.11
apache_software_foundationapache_seatunnel2.3.1 – 2.3.10
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.