CyberRota Analysis
AI-GeneratedApache Gravitino versions 1.0.0 through 1.2.1 are vulnerable to an authenticated server-side request forgery (SSRF) that allows attackers to send HTTP requests to internal network and cloud metadata endpoints through unvalidated job template URIs. This could lead to unauthorized access to sensitive data or services within the internal network. Organizations using affected versions should prioritize upgrading to version 1.3.0 to mitigate this risk.
Original NVD Description
Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and cloud metadata endpoints via unvalidated job template URIs. A vulnerability in Apache Gravitino. This issue affects Apache Gravitino: from 1.0.0 through 1.2.1. Users are recommended to upgrade to version 1.3.0, which fixes the issue.
Related CVEs
Other vulnerabilities affecting the same vendor(s)