216.73.216.133

CVE-2025-9571

· Published 10/12/2025 07:15 · Modified 12/12/2025 15:18

Labels: CVE-2025-9571 2025-12-10CVE-2025-9571CWE-502f45cbf4e-4146-4068-b7e1-655ffc2c548c

Essential information

Published
10/12/2025 07:15
Modified
12/12/2025 15:18
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A remote code execution (RCE) vulnerability exists in Google Cloud Data Fusion. A user with permissions to upload artifacts to a Data Fusion instance can execute arbitrary code within the core AppFabric component. This could allow the attacker to gain control over the Data Fusion instance, potentially leading to unauthorized access to sensitive data, modification of data pipelines, and exploration of the underlying infrastructure. The following CDAP versions include the necessary update to protect against this vulnerability: * 6.10.6+ * 6.11.1+  Users must immediately upgrade to them, or greater ones, available at: https://github.com/cdapio/cdap-build/releases .

NVD status

Status
Awaiting Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
f45cbf4e-4146-4068-b7e1-655ffc2c548c
NVD
View on NVD

References