Severity: low 

Affected versions:

- Apache Impala 4.1.0 through 4.5.2

Description:

Incorrect implementation of JWT/OAuth authentication in Impala executors in 
Apache Impala versions up to and including 4.5.2 which allows attacked to 
access resources served by the executor's webserver when that webserver is 
configured to accept JWT/OAuth tokens.  Bearer token (JWT) signatures are not 
validated resulting in the webserver accepting any valid JWT.
Users are recommended to either disable JWT/OAuth auth for Impala executors or 
upgrade to version 4.5.3, which fixes this issue.

Credit:

Andrew Rukin (Arenadata) (finder)

References:

https://impala.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-97720

Reply via email to