CVE-2025-53648: Apache Gravitino
Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.
SQL misconfiguration in the Gravitino UI, in versions 1.0.0 and below, can allow a malicious user to read or truncate files. Users are recommended to upgrade to version 1.0.0, which fixes this issue.
Affected products
- Apache Gravitino: from 0.5.0, before 1.0.0 (fixed in 1.0.0)
Published 2026-06-30. Last modified 2026-09-29.