Executive brief
Apache Gravitino, a high-performance metadata lake, is vulnerable to a security flaw where user-provided identifiers are not properly cleaned before being used in web addresses. This could allow an attacker to manipulate application requests, potentially leading to unauthorized access to data or unintended system behavior. Organizations should update to version 1.2.1 to resolve this issue.
Technical details
A URL path injection vulnerability exists in Apache Gravitino due to improper handling of URL encoding (CWE-177). The application fails to adequately encode user-supplied identifiers before incorporating them into URL paths. An attacker can exploit this by providing specially crafted identifiers containing path traversal or control characters, potentially allowing them to influence internal API calls or access unintended resources. This issue affects versions 1.0.0 through 1.2.0 and is resolved in version 1.2.1.
Affected products
- Apache Gravitino 1.0.0 to 1.2.0
Timeline
- 2026-07-13: disclosed
- 2026-07-13: advisory