Vulnerabilities
Vulnerable Software
Apache:  >> Impala  >> 4.1.0  Security Vulnerabilities
Insufficient authorization of Data Source tables in Impala 2.7-4.5 allows a client with privileges to upload a file to remote storage and create a table to execute arbitrary Java code. Users are recommended to upgrade to version 4.5.2, which fixes this issue.
CVSS Score
8.1
EPSS Score
0.005
Published
2026-09-09
Specifying tblproperties('avro.schema.url'=' http://...' ) or with a 'file:///' URI on a table in Impala 2.0.0 to 4.5.1 on all platforms allows an attacker to trigger a GET request to internal endpoints they may not have access to but that Impala does and the response my be exposed via parsing error messages. Users are recommended to upgrade to version 4.5.2, which fixes this issue.
CVSS Score
5.3
EPSS Score
0.005
Published
2026-09-09
Signature of Bearer token is not verified in last step of SAML2 authentication for Impala's hs2-http interface, allowing altering user name and acting as another user. This issue affects Apache Impala: >=4.0.0. Users are recommended to upgrade to version 4.5.2, which fixes this issue.
CVSS Score
9.8
EPSS Score
0.005
Published
2026-09-09


Contact Us

Shodan ® - All rights reserved