CyberRota Analysis
AI-GeneratedApache Impala versions 4.0.0 and above are vulnerable due to the lack of verification for the signature of Bearer tokens in the final step of SAML2 authentication, potentially allowing an attacker to impersonate another user. This vulnerability poses a significant risk to user identity and access control. Organizations utilizing affected versions should prioritize upgrading to version 4.5.2 to mitigate this security risk.
Original NVD Description
Signature of Bearer token is not verified in last step of SAML2 authentication for Impala's hs2-http interface, allowing altering user name and acting as another user. This issue affects Apache Impala: >=4.0.0. Users are recommended to upgrade to version 4.5.2, which fixes this issue.
Related CVEs
Other vulnerabilities affecting the same vendor(s)