A remote code execution (RCE) vulnerability exists in Google Cloud Data Fusion.
A user with permissions to upload artifacts to a Data Fusion instance can execute arbitrary code within the core AppFabric component.
This could allow the attacker to gain control over the Data Fusion instance, potentially leading to unauthorized access to sensitive data, modification of data pipelines, and exploration of the underlying infrastructure.
The following CDAP versions include the necessary update to protect against this vulnerability: * 6.10.6+
* 6.11.1+
Users must immediately upgrade to them, or greater ones, available at: https://github.com/cdapio/cdap-build/releases .
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://docs.cloud.google.com/support/bulletins#gcp-2025-076 |
|
History
Wed, 10 Dec 2025 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A remote code execution (RCE) vulnerability exists in Google Cloud Data Fusion. A user with permissions to upload artifacts to a Data Fusion instance can execute arbitrary code within the core AppFabric component. This could allow the attacker to gain control over the Data Fusion instance, potentially leading to unauthorized access to sensitive data, modification of data pipelines, and exploration of the underlying infrastructure. The following CDAP versions include the necessary update to protect against this vulnerability: * 6.10.6+ * 6.11.1+ Users must immediately upgrade to them, or greater ones, available at: https://github.com/cdapio/cdap-build/releases . | |
| Title | Arbitrary Code Execution in Google Cloud Data Fusion via Malicious Artifact Upload | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GoogleCloud
Published: 2025-12-10T07:02:59.932Z
Updated: 2025-12-10T07:02:59.932Z
Reserved: 2025-08-28T08:14:06.716Z
Link: CVE-2025-9571
No data.
Status : Received
Published: 2025-12-10T07:15:57.820
Modified: 2025-12-10T07:15:57.820
Link: CVE-2025-9571
No data.