AI analysis
Apache Impala through version 4.5.2 has a stored cross-site scripting flaw (CWE-79) in how query plans are shown in the Web UI. An SQL user who has only SELECT permission can place JavaScript in a table alias; that script is stored with the query and runs in another user's browser when that user opens the query plan. Impact is limited to the browser session of whoever views the plan (session theft or actions as that user in the Web UI), not remote code execution on the Impala cluster itself. Anyone running an affected Impala deployment whose users share the Web UI is exposed. There is no known public proof of concept and no report of exploitation in the wild; the issue is not on the CISA KEV list.
What to do: Upgrade Apache Impala to 4.5.3 or later. Until then, restrict access to the Impala Web UI (especially query-plan views) to trusted operators and review query history for suspicious table aliases containing script-like content.
Affected
| Apache Impala | up to and including 4.5.2 |
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
An SQL user using Impala up to and including version 4.5.2 with only SELECT permission can put JavaScript in a table alias and make it run in another user's browser when that user opens the query plan in Impala's Web UI. This is stored XSS (CWE-79). Users are recommended to upgrade to version 4.5.3.