Avatica is a framework for building database drivers. Avatica is defined by a wire API between a client and a server. The Avatica server is an HTTP server, the Avatica client is a JDBC driver, and the wire API is defined by JSON or Protobuf Buffers. The flexibility of the wire API and HTTP transport allows other Avatica clients to be built in any language, implementing any client specification. Avatica is a sub-project of the Apache Calcite project.
Apache Calcite Avatica (avatica-server) copies client-supplied JDBC connection properties into the backend connection with no filtering by default (JdbcMeta.openConnection: fullInfo.putAll(info) then DriverManager.getConnection), and authentication is disabled by default, so an unauthenticated remote client can inject driver properties such as allowLoadLocalInfile or autoDeserialize.
The backend JDBC URL itself is fixed by the operator, so the injected properties only produce impact against a backend that is attacker-controlled or reachable via man-in-the-middle: in that case allowLoadLocalInfile can make the backend read local files from the Avatica host (disclosure), and autoDeserialize can cause deserialization of attacker data, which becomes remote code execution only when a suitable gadget is present on the backend classpath.