AI analysis
Apache Impala executors through version 4.5.2 incorrectly implement JWT and OAuth authentication on the executor webserver. When that webserver is configured to accept bearer tokens, JWT signatures are not validated, so any well-formed JWT is accepted. An attacker who can reach the webserver can then access resources it serves without a legitimately signed token. Only Impala deployments that enable JWT/OAuth on executor webservers are affected; version 4.5.3 fixes the issue. No public proof of concept is known, and there is no report of exploitation in the wild.
What to do: Upgrade Apache Impala to 4.5.3, or disable JWT/OAuth authentication on Impala executors until you can upgrade. Limit executor webserver access to trusted networks and confirm whether JWT/OAuth is enabled on those webservers.
Affected
| Apache Software Foundation Apache Impala | up to and including 4.5.2 |
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Incorrect implementation of JWT/OAuth authentication in Impala executors in Apache Impala versions up to and including 4.5.2 which allows attacked to access resources served by the executor's webserver when that webserver is configured to accept JWT/OAuth tokens. Bearer token (JWT) signatures are not validated resulting in the webserver accepting any valid JWT. Users are recommended to either disable JWT/OAuth auth for Impala executors or upgrade to version 4.5.3, which fixes this issue.