CVE-2023-49198: Apache Seatunnel

High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.

Mysql security vulnerability in Apache SeaTunnel. Attackers can read files on the MySQL server by modifying the information in the MySQL URL allowLoadLocalInfile=true&allowUrlInLocalInfile=true&allowLoadLocalInfileInPath=/&maxAllowedPacket=655360 This issue affects Apache SeaTunnel: 1.0.0. Users are recommended to upgrade to version [1.0.1], which fixes the issue.

Affected products

  • Apache Seatunnel: version 1.0.0 only

Published 2024-08-21. Last modified 2026-06-17.