← לוח פגיעויות

CVE-2026-57866

גבוהה 8.8

תיאור (מקור, אנגלית)

Server side request forgery in Apache Impala versions 4.4.x and 4.5.x.  Authenticated Impala users with permissions to execute the ai_generate_text() function can exfiltrate secrets provided by the credential providers configured in the `hadoop.security.credential.provider.path` property of `core-site.xml`. The secret's key must be known to the user.

מדדים

CVSS 3.1
8.8 (HIGH) מקור הציון: CNA CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
1% (אחוזון 000) נכון ל-5/10/2026
CWE
CWE-918

מוצרים מושפעים

apache: impala

קישורים