SQL misconfiguration in the Gravitino UI, in versions 1.0.0 and below, can allow a malicious user to read or truncate files.
Users are recommended to upgrade to version 1.0.0, which fixes this issue.
Metrics
Affected Vendors & Products
References
History
Tue, 30 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 30 Jun 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SQL misconfiguration in the Gravitino UI, in versions 1.0.0 and below, can allow a malicious user to read or truncate files. Users are recommended to upgrade to version 1.0.0, which fixes this issue. | |
| Title | Apache Gravitino: SQL misconfiguration can access or truncate files | |
| Weaknesses | CWE-89 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-06-30T14:22:18.393Z
Reserved: 2025-07-08T05:17:44.991Z
Link: CVE-2025-53648
Updated: 2026-06-30T14:22:09.123Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-30T15:45:05Z