Skip to content

[GHSA-7ph3-grqh-pv9v] SQL misconfiguration in the Gravitino UI, in versions 1.0... - #10102

Draft
oscerd wants to merge 1 commit into
github:oscerd/advisory-improvement-10102from
oscerd:oscerd-GHSA-7ph3-grqh-pv9v
Draft

oscerd wants to merge 1 commit into
github:oscerd/advisory-improvement-10102from
oscerd:oscerd-GHSA-7ph3-grqh-pv9v

Conversation

@oscerd

@oscerd oscerd commented Oct 2, 2026

Copy link
Copy Markdown

[GHSA-7ph3-grqh-pv9v] SQL misconfiguration in the Gravitino UI, in versions 1.0...

Updates

  • Affected products
  • Source code location

Comments
Affected package, version range and source code location are taken from the official Apache Gravitino security advisory: https://lists.apache.org/thread/s0hytcv17z52dwp5dojjjwgrtqtyh2xk

The GHSA text says "the Gravitino UI, in versions 1.0.0 and below" and then "upgrade to version 1.0.0", which cannot both be read literally. The "Affected versions" header of the same announcement is precise and consistent with the stated fix: "Apache Gravitino (org.apache.gravitino:catalog-jdbc-common) 0.5.0 before 1.0.0", so that is used here. The published versions falling inside that range are 0.6.0-incubating, 0.6.1-incubating and 0.7.0-incubating.

Claude Code on behalf of oscerd

🤖 Generated with Claude Code

…rsions 1.0...

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Signed-off-by: Andrea Cosentino <ancosen@gmail.com>
@github-actions
github-actions Bot changed the base branch from main to oscerd/advisory-improvement-10102 October 2, 2026 08:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant