Skip to main content

Vendor/product archive

apache / seatunnel CVEs

Beta · best-effort

3 CVEs tagged to apache / seatunnel1 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2025-32896

Published Jun 19, 2025

# Summary Unauthorized users can perform Arbitrary File Read and Deserialization attack by submit job using restful api-v1. # Details Unauthorized users can access `/hazelcast/r…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-49198

Published Aug 21, 2024

Mysql security vulnerability in Apache SeaTunnel. Attackers can read files on the MySQL server by modifying the information in the MySQL URL allowLoadLocalInfile=true&allowUrlI…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-48396

Published Jul 30, 2024

Web Authentication vulnerability in Apache SeaTunnel. Since the jwt key is hardcoded in the application, an attacker can forge any token to log in any user. Attacker can get secr…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1