Apache Gravitino
- >= 1.0.0, < 1.2.1
A URL path injection vulnerability has been identified in Apache Gravitino versions 1.0.0 prior to 1.2.1. This issue arises from unencoded user-supplied identifiers, which can be exploited to traverse paths and access unintended API endpoints via the MCP REST client.
Exploitation of this vulnerability allows for path traversal to unintended API endpoints, potentially leading to unauthorized access or manipulation of resources.
Users are advised to upgrade to Apache Gravitino version 1.2.1 or later, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.