5.3
CVE-2026-54048
- EPSS 0.58%
- Veröffentlicht 09.09.2026 10:34:01
- Zuletzt bearbeitet 10.09.2026 20:38:42
- Erkennungen
Apache Impala: Avro Schema URL Server-Side Request Forgery
Specifying tblproperties('avro.schema.url'=' http://...' ) or with a 'file:///' URI on a table in Impala 2.0.0 to 4.5.1 on all platforms allows an attacker to trigger a GET request to internal endpoints they may not have access to but that Impala does and the response my be exposed via parsing error messages.
Users are recommended to upgrade to version 4.5.2, which fixes this issue.| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.58% | 0.46 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-918 Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
https://lists.apache.org/thread/cn3q4s8yx924ndlm3gt04o6g4rfm980c
http://www.openwall.com/lists/oss-security/2026/09/08/21