Apache

Impala

14 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.16%
  • Veröffentlicht 07.10.2026 08:48:45
  • Zuletzt bearbeitet 07.10.2026 19:17:45

An SQL user using Impala up to and including version 4.5.2 with only SELECT permission can put JavaScript in a table alias and make it run in another user's browser when that user opens the query plan in Impala's Web UI. This is stored XSS (CWE-79). ...

  • EPSS 0.34%
  • Veröffentlicht 07.10.2026 08:47:12
  • Zuletzt bearbeitet 07.10.2026 19:17:44

Path traversal of 'trusted_jar_paths' in Impala 4.5.2 allows an attacker-controlled JAR to be loaded via a relative path where the prefix matches a path specified in 'trusted_jar_paths'. The startup flag 'trusted_jar_paths' references URIs for lo...

  • EPSS 0.32%
  • Veröffentlicht 07.10.2026 08:46:45
  • Zuletzt bearbeitet 07.10.2026 19:17:45

Incorrect implementation of JWT/OAuth authentication in Impala executors in Apache Impala versions up to and including 4.5.2 which allows attacked to access resources served by the executor's webserver when that webserver is configured to accept JWT/...

  • EPSS 0.56%
  • Veröffentlicht 09.09.2026 10:40:51
  • Zuletzt bearbeitet 10.09.2026 20:36:32

Insufficient authorization of Data Source tables in Impala 2.7-4.5 allows a client with privileges to upload a file to remote storage and create a table to execute arbitrary Java code. Users are recommended to upgrade to version 4.5.2, which fixes th...

  • EPSS 0.6%
  • Veröffentlicht 09.09.2026 10:39:47
  • Zuletzt bearbeitet 10.09.2026 20:36:43

Server side request forgery in Apache Impala versions 4.4.x and 4.5.x.  Authenticated Impala users with permissions to execute the ai_generate_text() function can exfiltrate secrets provided by the credential providers configured in the `hadoop.secur...

  • EPSS 0.47%
  • Veröffentlicht 09.09.2026 10:36:55
  • Zuletzt bearbeitet 10.09.2026 20:38:05

Signature of Bearer token is not verified in last step of SAML2 authentication for Impala's hs2-http interface, allowing altering user name and acting as another user. This issue affects Apache Impala: >=4.0.0. Users are recommended to upgrade ...

  • EPSS 0.58%
  • Veröffentlicht 09.09.2026 10:34:01
  • Zuletzt bearbeitet 10.09.2026 20:38:42

Specifying tblproperties('avro.schema.url'=' http://...' ) or with a 'file:///' URI on a table in Impala 2.0.0 to 4.5.1 on all platforms allows an attacker to trigger a GET request to internal endpoints they may not have access to but that Impala doe...

  • EPSS 3.32%
  • Veröffentlicht 22.07.2021 10:15:07
  • Zuletzt bearbeitet 21.11.2024 05:59:08

Impala sessions use a 16 byte secret to verify that the session is not being hijacked by another user. However, these secrets appear in the Impala logs, therefore Impala users with access to the logs can use another authenticated user's sessions with...

  • EPSS 0.99%
  • Veröffentlicht 05.11.2019 20:15:11
  • Zuletzt bearbeitet 21.11.2024 04:18:22

In Apache Impala 2.7.0 to 3.2.0, an authenticated user with access to the IDs of active Impala queries or sessions can interact with those sessions or queries via a specially-constructed request and thereby potentially bypass authorization and audit ...

  • EPSS 1.22%
  • Veröffentlicht 24.10.2018 20:29:00
  • Zuletzt bearbeitet 21.11.2024 03:44:02

Missing authorization check in Apache Impala before 3.0.1 allows a Kerberos-authenticated but unauthorized user to inject random data into a running query, leading to wrong results for a query.