AI analysis
Apache Impala 4.5.2 has a path traversal flaw (CWE-23) in how the trusted_jar_paths startup flag is applied when loading JARs. An attacker can supply a relative path whose prefix matches a configured trusted URI so Impala loads a JAR from a different location on the same local or remote filesystem, including a JAR previously uploaded through Impala DDL such as CREATE DATA SOURCE or CREATE TABLE. Path traversal cannot change the URI scheme, and the attack only works when an administrator has set trusted_jar_paths to a non-empty value. Successful exploitation can cause Impala to execute code from an attacker-controlled JAR. No public proof of concept is known, the issue is not listed in CISA KEV, and CVSS has not yet been scored.
What to do: Upgrade Apache Impala to 4.5.3. Until then, leave trusted_jar_paths unset or empty unless JAR loading is required, and restrict who can run CREATE DATA SOURCE and CREATE TABLE so untrusted JARs cannot be placed on filesystems referenced by trusted paths.
Affected
| Apache Impala | 4.5.2 (fixed in 4.5.3) |
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Path traversal of 'trusted_jar_paths' in Impala 4.5.2 allows an attacker-controlled JAR to be loaded via a relative path where the prefix matches a path specified in 'trusted_jar_paths'. The startup flag 'trusted_jar_paths' references URIs for loading files from local or remote filesystems. Path traversal can't override the schema, but can result in loading a JAR that has been uploaded to a different location in that filesystem via Impala DDLs such as CREATE DATA SOURCE and CREATE TABLE. Path traversal can only be used if a trusted path exists, so this attack requires 'trusted_jar_paths' have a non-empty value configured by the Impala admin. Users are recommended to upgrade to version 4.5.3, which fixes this issue.