Executive brief
Apache Gravitino, a metadata management system, contains a configuration flaw in its user interface. This vulnerability could allow a malicious user to read or delete (truncate) sensitive files on the system. Organizations should upgrade to version 1.0.0 to prevent unauthorized data access or service disruption.
Technical details
A SQL injection vulnerability (CWE-89) exists in the Apache Gravitino UI due to a misconfiguration in the SQL command handling. The flaw is located within the catalog-jdbc-common component. An attacker with access to the UI can exploit this to perform unauthorized file operations, specifically reading or truncating files on the host system. The vulnerability affects versions 0.5.0 up to 1.0.0. Users are advised to upgrade to version 1.0.0 or later to remediate the issue.
Affected products
- Apache Software Foundation Apache Gravitino 0.5.0 to 1.0.0
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched: Fixed in version 1.0.0