在 Apache Impala 最高至 4.5.2 版本中,即使 SQL 用户仅拥有 SELECT 权限,也可能通过在表别名中注入 JavaScript 代码,在其他用户通过 Impala Web UI 打开查询计划时触发该脚本的执行。此为存储型跨站脚本漏洞(Stored XSS,CWE-79)。建议用户升级至版本 4.5.3 以修复此问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Impala | 2.7.0 ~ 4.5.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-97146 | 4.8 MEDIUM | Apache YuniKorn: Admission control bypass via system label forgery |
| CVE-2026-78243 | 2.1 LOW | Apache YuniKorn: LDAP Group provider panics on lowercase attribute name |
| CVE-2026-92393 | 2.0 LOW | Apache YuniKorn: Admission control bypass via workload UPDATE operation |
| CVE-2026-90466 | Apache Impala: Path traversal executes JARs outside trusted paths | |
| CVE-2026-97720 | Apache Impala: Impala Executor Webserver Auth Bypass |
No comments yet