CyberRota Analysis
AI-GeneratedImpala versions 2.7 to 4.5 are vulnerable due to insufficient authorization in Data Source tables, enabling clients with upload privileges to execute arbitrary Java code by creating a table. This vulnerability poses a significant risk as it could lead to unauthorized code execution and potential data breaches. Organizations using affected Impala versions should prioritize upgrading to version 4.5.2 to mitigate this security risk.
Original NVD Description
Insufficient authorization of Data Source tables in Impala 2.7-4.5 allows a client with privileges to upload a file to remote storage and create a table to execute arbitrary Java code. Users are recommended to upgrade to version 4.5.2, which fixes this issue.
Related CVEs
Other vulnerabilities affecting the same vendor(s)