CyberRota Analysis
AI-GeneratedImpala versions 2.0.0 to 4.5.1 are vulnerable due to the ability to specify external schema URLs, potentially allowing attackers to trigger unauthorized GET requests to internal endpoints. This could lead to the exposure of sensitive information through parsing error messages. Organizations using affected versions should prioritize upgrading to version 4.5.2 to mitigate this risk.
Original NVD Description
Specifying tblproperties('avro.schema.url'=' http://...' ) or with a 'file:///' URI on a table in Impala 2.0.0 to 4.5.1 on all platforms allows an attacker to trigger a GET request to internal endpoints they may not have access to but that Impala does and the response my be exposed via parsing error messages. Users are recommended to upgrade to version 4.5.2, which fixes this issue.
Related CVEs
Other vulnerabilities affecting the same vendor(s)