Apache Gravitino
- >= 1.0.0, <= 1.2.1
A vulnerability allowing authenticated server-side request forgery (SSRF) has been identified in the JobManager component of Apache Gravitino. This issue arises in versions 1.0.0 through 1.2.1 and allows HTTP requests to be sent from the server to internal network resources and cloud metadata endpoints. The vulnerability is exploited through unvalidated job template URIs.
Exploitation of this vulnerability allows for authenticated server-side request forgery, enabling the server to make HTTP requests to internal resources or cloud metadata services, potentially leading to unauthorized data access or manipulation.
Users are advised to upgrade to Apache Gravitino version 1.3.0, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.