PT-2026-88923 · Apache · Apache Impala
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Server side request forgery in Apache Impala versions 4.4.x and 4.5.x. Authenticated Impala users with permissions to execute the ai generate text() function can exfiltrate secrets provided by the credential providers configured in the
hadoop.security.credential.provider.path property of core-site.xml. The secret's key must be known to the user.Correção
SSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Apache Impala