← לוח פגיעויות

CVE-2026-54048

בינונית 5.3

תיאור (מקור, אנגלית)

Specifying tblproperties('avro.schema.url'=' http://...' ) or with a 'file:///' URI on a table in Impala 2.0.0 to 4.5.1 on all platforms allows an attacker to trigger a GET request to internal endpoints they may not have access to but that Impala does and the response my be exposed via parsing error messages. Users are recommended to upgrade to version 4.5.2, which fixes this issue.

מדדים

CVSS 3.1
5.3 (MEDIUM) מקור הציון: CNA CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS — סבירות ניצול
1% (אחוזון 000) נכון ל-5/10/2026
CWE
CWE-918

מוצרים מושפעים

apache: impala

קישורים