Apache SeaTunnel Vulnerability Enables Unauthorized Deserialization Attacks
ID: 15ab50db-8a51-57ee-bfe4-b4e31eed496c
STIX ID: report--15ab50db-8a51-57ee-bfe4-b4e31eed496c
Feed Name: Cyber Press
Apache SeaTunnel contains a vulnerability (CVE-2025-32896) in the REST API v1 /hazelcast/rest/maps/submit-job endpoint that permits unauthenticated job submissions; attackers can inject malicious parameters to cause arbitrary file reads and Java deserialization leading to remote code execution. The flaw affects SeaTunnel versions up to 2.3.10 and was fixed in 2.3.11 (May 27, 2025); recommended mitigations include immediate upgrade to 2.3.11+, disabling REST API v1, migrating to authenticated API v2, enabling mutual TLS between nodes, and monitoring /submit-job access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
