{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aapachegravitino/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:apache:gravitino:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":6.5,"id":"CVE-2026-49876"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Gravitino"],"_cs_severities":["low"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Apache"],"content_html":"\u003cp\u003eApache Gravitino versions 1.0.0 through 1.2.1 are susceptible to a Server-Side Request Forgery (SSRF) vulnerability identified as CVE-2026-49876. The vulnerability resides within the \u003ccode\u003efetchFileFromUri()\u003c/code\u003e method in \u003ccode\u003eJobManager.java\u003c/code\u003e, which processes job template fields such as executable scripts, jars, and archives. The application fails to validate the destination URI provided by users, permitting the use of http, https, and ftp schemes. By registering a malicious job template, an authenticated attacker can force the server to fetch content from internal network resources or cloud metadata services. The downloaded content is subsequently written to the server's staging directory. This impact is significant for environments leveraging Gravitino in cloud deployments, where the application may be used to exfiltrate cloud instance identity tokens via the metadata service.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker authenticates to the Apache Gravitino REST API using valid user credentials.\u003c/li\u003e\n\u003cli\u003eAttacker interacts with the \u003ccode\u003e/api/metalakes/{metalake}/jobs/templates\u003c/code\u003e endpoint to register a new job template.\u003c/li\u003e\n\u003cli\u003eAttacker specifies a crafted URI in the \u003ccode\u003eexecutable\u003c/code\u003e field of the job template, pointing to an internal resource (e.g., \u003ccode\u003ehttp://169.254.169.254/latest/meta-data/\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eAttacker triggers the job execution via the \u003ccode\u003e/api/metalakes/{metalake}/jobs/runs\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003cli\u003eThe application's \u003ccode\u003efetchFileFromUri()\u003c/code\u003e method processes the job template and initiates an outbound request to the attacker-supplied URI.\u003c/li\u003e\n\u003cli\u003eThe server fetches the remote resource and saves it to the local staging directory via \u003ccode\u003eFileUtils.copyURLToFile()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAttacker retrieves the content from the staging directory or observes interactions via an OOB callback server if blind SSRF techniques are employed.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an authenticated attacker to perform unauthorized internal reconnaissance, access sensitive configuration files, or exfiltrate cloud environment metadata (such as IAM role credentials). The scope affects all Gravitino instances between versions 1.0.0 and 1.2.1, with Ubuntu 22.04 environments explicitly confirmed as a target platform.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Apache Gravitino to the latest version that includes the patch for CVE-2026-49876.\u003c/li\u003e\n\u003cli\u003eRestrict access to the Gravitino REST API to trusted users and IP ranges.\u003c/li\u003e\n\u003cli\u003eEnable egress filtering on the application server hosting Gravitino to prevent unauthorized connections to sensitive internal subnets and cloud metadata endpoints (e.g., 169.254.169.254).\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to monitor for suspicious job template registration patterns via web server logs.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-11T15:06:57Z","date_published":"2026-08-11T15:06:57Z","id":"https://feed.craftedsignal.io/briefs/2026-08-apache-gravitino-ssrf/","summary":"Apache Gravitino versions 1.0.0 through 1.2.1 contain an authenticated SSRF vulnerability (CVE-2026-49876) allowing attackers to perform internal network reconnaissance or access metadata services.","title":"Apache Gravitino Authenticated Server-Side Request Forgery","url":"https://feed.craftedsignal.io/briefs/2026-08-apache-gravitino-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:apache:gravitino:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}