CyberRota Analysis
AI-GeneratedApache Impala versions 4.4.x and 4.5.x are vulnerable to a server-side request forgery (SSRF) that allows authenticated users with access to the `ai_generate_text()` function to exfiltrate sensitive secrets from configured credential providers. The impact includes potential exposure of confidential information, as users can retrieve secrets if they know the corresponding keys. Organizations using these Impala versions, particularly those with users who have elevated permissions, should prioritize addressing this vulnerability to mitigate risks of data leakage.
Original NVD Description
Server side request forgery in Apache Impala versions 4.4.x and 4.5.x. Authenticated Impala users with permissions to execute the ai_generate_text() function can exfiltrate secrets provided by the credential providers configured in the `hadoop.security.credential.provider.path` property of `core-site.xml`. The secret's key must be known to the user.
Related CVEs
Other vulnerabilities affecting the same vendor(s)