imPC@ndo IT

Tracker / CVE-2025-53648

CVE-2025-53648

Medium 5.4

SQL misconfiguration in the Gravitino UI, in versions 1.0.0 and below, can allow a malicious user to read or truncate files. Users are recommended to upgrade to version 1.0.0, which fixes this issue.

Affected products and versions

apache gravitino · 0.5.0 → 1.0.0

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References