Apache Gravitino Authenticated Server-Side Request Forgery Vulnerability in JobManager

Vulnerability

A vulnerability allowing authenticated server-side request forgery (SSRF) has been identified in the JobManager component of Apache Gravitino. This issue arises in versions 1.0.0 through 1.2.1 and allows HTTP requests to be sent from the server to internal network resources and cloud metadata endpoints. The vulnerability is exploited through unvalidated job template URIs.

Impact

Exploitation of this vulnerability allows for authenticated server-side request forgery, enabling the server to make HTTP requests to internal resources or cloud metadata services, potentially leading to unauthorized data access or manipulation.

Remediation

Users are advised to upgrade to Apache Gravitino version 1.3.0, which addresses this vulnerability.

Added: Jul 13, 2026, 11:56 AM
Updated: Jul 13, 2026, 11:56 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.1
exploitability
5.2
remediation
0.0
relevance
9.3
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.