Junglewise Threat Intelligence

CVE-2025-53648: Apache Gravitino SQL injection in UI

CVE-2025-53648 · Severity: info · CVSS 0 · Published 2026-06-30

Technologies: Apache Software Foundation Gravitino. Vendors: Apache Software Foundation.

Executive brief

Apache Gravitino, a metadata management system, contains a configuration flaw in its user interface. This vulnerability could allow a malicious user to read or delete (truncate) sensitive files on the system. Organizations should upgrade to version 1.0.0 to prevent unauthorized data access or service disruption.

Technical details

A SQL injection vulnerability (CWE-89) exists in the Apache Gravitino UI due to a misconfiguration in the SQL command handling. The flaw is located within the catalog-jdbc-common component. An attacker with access to the UI can exploit this to perform unauthorized file operations, specifically reading or truncating files on the host system. The vulnerability affects versions 0.5.0 up to 1.0.0. Users are advised to upgrade to version 1.0.0 or later to remediate the issue.

Affected products

  • Apache Software Foundation Apache Gravitino 0.5.0 to 1.0.0

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched: Fixed in version 1.0.0

References

Related threats