Severity: important 

Affected versions:

- Apache Impala 4.4.0 through 4.5.1

Description:

Server side request forgery in Apache Impala versions 4.4.x and 4.5.x.  
Authenticated Impala users with permissions to execute the ai_generate_text() 
function can exfiltrate secrets provided by the credential providers configured 
in the `hadoop.security.credential.provider.path` property of `core-site.xml`. 
The secret's key must be known to the user.

Credit:

Andrey Rukin (Arenadata) (reporter)

References:

https://impala.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-57866

Reply via email to