Apache Gravitino: Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java code on the server via H2's INIT parameter
63Vexday Risk Score
Corrige pronto. Ella tiene exploit funcional público.
ssvc Attendcvss 9.1epss 1.0%
de la publicación al arma40 días
Publicada en NVD8 jul
1ª PoC+40d
probabilidad de explotación
1.0%top 41% de las CVE
explotación observada
noninguna fuente lo reporta
1 exploit(s) público(s)
Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java code on the server via H2's INIT parameter. Vulnerability in Apache Gravitino.
This issue affects Apache Gravitino: before 1.2.1.
Users are recommended to upgrade to version 1.2.1, which fixes the issue.
This issue only happens when using H2, and H2 is mainly used for testing and local development. Also, Gravitino is typically deployed in the internal environment, so the severity is low.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Productos afectados
Apache Software Foundation · Apache GravitinoPoCs públicas encontradas — 1
githubgithub.com/Lulztigre/cve-2026-41042★ 0⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.