Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In Apache Impala (incubating) before 2.10.0, a malicious user with "ALTER" permissions on an Impala table can access any other Kudu table data by altering the table properties to make it "external" and then changing the underlying table mapping to point to other Kudu tables. This violates and works around the authorization requirement that creating a Kudu external table via Impala requires an "ALL" privilege at the server scope. This privilege requirement for "CREATE" commands is enforced to precisely avoid this scenario where a malicious user can change the underlying Kudu table mapping. The fix is to enforce the same privilege requirement for "ALTER" commands that would make existing non-external Kudu tables external.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apache Impala(incubating) 安全漏洞
Vulnerability Description
Apache Impala(incubating)是美国阿帕奇(Apache)软件基金会的一套大规模、分布式并行处理的数据库查询系统。该系统能够查询存储在Hadoop(大数据分析软件)中的HDFS(分布式文件系统)和HBase(数据库)中的PB级大数据。 Apache Impala(incubating) 2.10.0之前的版本中存在安全漏洞。攻击者可通过更改表单属性,并将底层表映射到其他的Kudu表利用该漏洞访问任意的Kudu表单数据。
CVSS Information
N/A
Vulnerability Type
N/A