CVE-2021-28131
- EPSS 0.59%
- Published 22.07.2021 10:15:07
- Last modified 21.11.2024 05:59:08
Impala sessions use a 16 byte secret to verify that the session is not being hijacked by another user. However, these secrets appear in the Impala logs, therefore Impala users with access to the logs can use another authenticated user's sessions with...
CVE-2019-10084
- EPSS 0.1%
- Published 05.11.2019 20:15:11
- Last modified 21.11.2024 04:18:22
In Apache Impala 2.7.0 to 3.2.0, an authenticated user with access to the IDs of active Impala queries or sessions can interact with those sessions or queries via a specially-constructed request and thereby potentially bypass authorization and audit ...
CVE-2018-11785
- EPSS 0.11%
- Published 24.10.2018 20:29:00
- Last modified 21.11.2024 03:44:02
Missing authorization check in Apache Impala before 3.0.1 allows a Kerberos-authenticated but unauthorized user to inject random data into a running query, leading to wrong results for a query.
CVE-2018-11792
- EPSS 0.55%
- Published 24.10.2018 20:29:00
- Last modified 21.11.2024 03:44:02
In Apache Impala before 3.0.1, ALTER TABLE/VIEW RENAME required ALTER on the old table. This may pose a potential security risk, such as having ALTER on a table and ALL on a particular database allows a user to move the table to a database with ALL, ...
CVE-2017-9792
- EPSS 0.21%
- Published 04.10.2017 01:29:03
- Last modified 20.04.2025 01:37:25
In Apache Impala (incubating) before 2.10.0, a malicious user with "ALTER" permissions on an Impala table can access any other Kudu table data by altering the table properties to make it "external" and then changing the underlying table mapping to po...
CVE-2017-5640
- EPSS 1.3%
- Published 10.07.2017 20:29:00
- Last modified 20.04.2025 01:37:25
It was noticed that a malicious process impersonating an Impala daemon in Apache Impala (incubating) 2.7.0 to 2.8.0 could cause Impala daemons to skip authentication checks when Kerberos is enabled (but TLS is not). If the malicious server responds w...
CVE-2017-5652
- EPSS 0.33%
- Published 10.07.2017 20:29:00
- Last modified 20.04.2025 01:37:25
During a routine security analysis, it was found that one of the ports in Apache Impala (incubating) 2.7.0 to 2.8.0 sent data in plaintext even when the cluster was configured to use TLS. The port in question was used by the StatestoreSubscriber clas...