Severity: important 

Affected versions:

- Apache Impala 2.7.0 through 4.5.1

Description:

Insufficient authorization of Data Source tables in Impala 2.7-4.5 allows a 
client with privileges to upload a file to remote storage and create a table to 
execute arbitrary Java code.
Users are recommended to upgrade to version 4.5.2, which fixes this issue.

Credit:

zhaokaifei ChinaTelecom (reporter)

References:

https://impala.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-65181

Reply via email to