Apache · Apache Gravitino · CVE-2025-53648
**Name of the Vulnerable Software and Affected Versions**
Apache Gravitino versions prior to 1.0.0
**Description**
A SQL misconfiguration in the Gravitino UI allows a malicious user to read or truncate files.
**Recommendations**
Upgrade to version 1.0.0.