Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Darpan Patel

#20716of 56,330
13.6Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2026-57680
6.5
2026-07-13
Apache · Apache Gravitino · CVE-2026-49876
**Name of the Vulnerable Software and Affected Versions** Apache Gravitino versions 1.0.0 through 1.2.1 **Description** An authenticated Server-Side Request Forgery (SSRF) exists in the Gravitino JobManager. This allows an attacker to trigger server-side HTTP requests to internal networks and cloud metadata endpoints by providing unvalidated job template URIs. SSRF is a flaw where a server is tricked into making requests to an unintended location. **Recommendations** Upgrade to version 1.3.0.
PT-2025-6693
7.1
2025-02-12
Apache · Apache Atlas · CVE-2024-46910
**Name of the Vulnerable Software and Affected Versions** Apache Atlas versions 2.3.0 and earlier **Description** An authenticated user can perform XSS and potentially impersonate another user. This issue allows for cross-site scripting attacks, which could lead to unauthorized actions being taken on behalf of other users. **Recommendations** For Apache Atlas versions 2.3.0 and earlier, upgrade to version 2.4.0, which fixes the issue. As a temporary workaround, consider restricting access to sensitive features that could be exploited through XSS attacks until the update is applied.