Impact
Authenticated users can submit arbitrary job template URIs to the Gravitino JobManager, which are then used without validation to perform HTTP requests. This flaw permits server‑side request forgery that lets an attacker retrieve data or interact with internal network services or cloud metadata endpoints that are normally inaccessible from the public internet, potentially exposing sensitive configuration or secret material.
Affected Systems
The vulnerability exists in Apache Gravitino versions 1.0.0 through 1.2.1. Systems that provide authenticated access to the JobManager—such as users with job submission privileges in a data catalog or processing environment—are affected. The flaw is not present in the patched 1.3.0 release and later versions.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. With an EPSS below 1% the likelihood of public exploitation is low, and it is not listed in the CISA KEV catalog. Nevertheless, because the flaw requires legitimate authentication and unvalidated URI input, an attacker can force the server to contact internal IP ranges or cloud metadata services, potentially leaking internal details or secrets.
OpenCVE Enrichment