Unauthorized users can perform Arbitrary File Read and Deserialization attack by submit job using restful api-v1.
Unauthorized users can access /hazelcast/rest/maps/submit-job to submit
job.
An attacker can set extra params in mysql url to perform Arbitrary File
Read and Deserialization attack.
This issue affects Apache SeaTunnel: <=2.3.10
Users are recommended to upgrade to version 2.3.11, and enable restful api-v2 & open https two-way authentication , which fixes the issue.
{
"cwe_ids": [
"CWE-306"
],
"github_reviewed": true,
"github_reviewed_at": "2025-06-19T16:19:58Z",
"nvd_published_at": "2025-06-19T11:15:24Z",
"severity": "LOW"
}