Apache / Impala
11 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-65181 | Apache Impala: RCE via External Data Source Class Loading | HIGH | 8.1 | Sep 9, 2026 |
| CVE-2026-57866 | Apache Impala: Secrets Exfiltration via SSRF | HIGH | 8.8 | Sep 9, 2026 |
| CVE-2026-56207 | Apache Impala: SAML authentication bypass via forged bearer token | CRITICAL | 9.8 | Sep 9, 2026 |
| CVE-2026-54048 | Apache Impala: Avro Schema URL Server-Side Request Forgery | MEDIUM | 5.3 | Sep 9, 2026 |
| CVE-2021-28131 | Impala logs contain secrets | HIGH | 7.5 | Jul 22, 2021 |
| CVE-2019-10084 | In Apache Impala 2.7.0 to 3.2.0, an authenticated user with access to the IDs of active Impala queries or sessions can interact with those sessions or queries… | HIGH | 7.5 | Nov 5, 2019 |
| CVE-2018-11792 | In Apache Impala before 3.0.1, ALTER TABLE/VIEW RENAME required ALTER on the old table. This may pose a potential security risk, such as having ALTER on a tabl… | CRITICAL | 9.8 | Oct 24, 2018 |
| CVE-2018-11785 | Missing authorization check in Apache Impala before 3.0.1 allows a Kerberos-authenticated but unauthorized user to inject random data into a running query, lea… | MEDIUM | 6.5 | Oct 24, 2018 |
| CVE-2017-9792 | In Apache Impala (incubating) before 2.10.0, a malicious user with "ALTER" permissions on an Impala table can access any other Kudu table data by altering the… | MEDIUM | 6.5 | Oct 3, 2017 |
| CVE-2017-5652 | During a routine security analysis, it was found that one of the ports in Apache Impala (incubating) 2.7.0 to 2.8.0 sent data in plaintext even when the cluste… | HIGH | 7.5 | Jul 10, 2017 |
| CVE-2017-5640 | It was noticed that a malicious process impersonating an Impala daemon in Apache Impala (incubating) 2.7.0 to 2.8.0 could cause Impala daemons to skip authenti… | CRITICAL | 9.8 | Jul 10, 2017 |
Showing 1 to 11 of 11 CVEs