Apache Apache Gravitino是美国Apache基金会开源的一款高性能、地理分布式、联邦式元数据湖,提供统一的数据和 AI 资产管理与治理框架。 Apache Gravitino 1.0.0及之前版本存在SQL注入漏洞,该漏洞源于SQL配置错误,可能导致恶意用户读取或截断文件。以下版本受到影响:0.5.0版本、0.5.1版本、0.6.0版本、0.6.1版本、0.7.0版本、0.8.0版本、0.8.1版本、0.9.0版本、0.9.1版本和0.9.2版本。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Gravitino | 0.5.0< 1.0.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Gravitino | 0.5.0 ~ 1.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54475 | Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Temporary destination owners | |
| CVE-2026-53917 | Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Client, Apache ActiveMQ Broker: Unbo | |
| CVE-2026-53916 | Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: Unbounded header buffer in ST | |
| CVE-2026-52760 | Apache ActiveMQ, Apache ActiveMQ Web Console: Stored XSS via Unescaped values in ActiveMQ | |
| CVE-2026-50750 | Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: Pre-authentication OpenWire | |
| CVE-2026-50734 | Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All: Pre-authentication OpenWire | |
| CVE-2026-49877 | Apache ActiveMQ: Authenticated web users retain admin access by default in the Web Console | |
| CVE-2026-49432 | Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: STOMP negative content-length | |
| CVE-2026-49434 | Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: LdapNetworkConnector instant |
No comments yet