Apache

Gravitino

4 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.48%
  • Veröffentlicht 13.07.2026 09:08:51
  • Zuletzt bearbeitet 13.07.2026 22:24:21

URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino. This issue affects Apache Gravitino: from 1.0.0 before 1.2.1. Users are recommended to upgrade to version 1.2.1, which fixes the issue.

  • EPSS 0.4%
  • Veröffentlicht 13.07.2026 08:45:35
  • Zuletzt bearbeitet 13.07.2026 22:22:55

Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and cloud metadata endpoints via unvalidated job template URIs. A vulnerability in Apache Gravitino. This issue affects Apache Gravitino: from 1.0.0 thro...

  • EPSS 0.98%
  • Veröffentlicht 08.07.2026 11:38:55
  • Zuletzt bearbeitet 08.07.2026 20:16:49

Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java code on the server via H2's INIT parameter. Vulnerability in Apache Gravitino. This issue affects Apache Gravitino: before 1.2.1...

  • EPSS 0.35%
  • Veröffentlicht 30.06.2026 13:36:00
  • Zuletzt bearbeitet 29.09.2026 19:10:00

SQL misconfiguration in the Gravitino UI, in versions 1.0.0 and below, can allow a malicious user to read or truncate files. Users are recommended to upgrade to version 1.0.0, which fixes this issue.