Impala 4.5.2 中的 存在路径遍历漏洞,允许攻击者通过相对路径加载受控的 JAR 文件,前提是该相对路径的前缀匹配 中指定的路径。 启动参数 引用了用于从本地或远程文件系统加载文件的统一资源标识符(URI)。虽然路径遍历无法覆盖协议(schema),但可能导致通过 Impala DDL 语句(如 CREATE DATA SOURCE 和 CREATE TABLE)将已上传至该文件系统中其他位置的 JAR 文件加载到系统中。只有当存在受信任路径时,路径遍历攻击才得以实施,因此该攻击要求 Impala 管理员
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Impala | 4.5.2 ~ 4.5.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-97146 | 4.8 MEDIUM | Apache YuniKorn: Admission control bypass via system label forgery |
| CVE-2026-78243 | 2.1 LOW | Apache YuniKorn: LDAP Group provider panics on lowercase attribute name |
| CVE-2026-92393 | 2.0 LOW | Apache YuniKorn: Admission control bypass via workload UPDATE operation |
| CVE-2026-93684 | Apache Impala: Stored XSS in Impala query plans | |
| CVE-2026-97720 | Apache Impala: Impala Executor Webserver Auth Bypass |
No comments yet