Known Vulnerabilities for Impala by Apache
Listed below are 10 of the newest known vulnerabilities associated with "Impala" by "Apache".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-65181 json | Insufficient authorization of Data Source tables in Impala 2.7-4.5 allows a client with privileges to upload a file to remote... | Not Provided | 2026-09-09 | 2026-09-09 |
| CVE-2026-57866 json | Server side request forgery in Apache Impala versions 4.4.x and 4.5.x. Authenticated Impala users with permissions to execu... | Not Provided | 2026-09-09 | 2026-09-10 |
| CVE-2026-56207 json | Signature of Bearer token is not verified in last step of SAML2 authentication for Impala's hs2-http interface, allowing alte... | Not Provided | 2026-09-09 | 2026-09-10 |
| CVE-2026-54048 json | Specifying tblproperties('avro.schema.url'=' http://...' ) or with a 'file:///' URI on a table in Impala 2.0.0 to 4.5.1 on al... | Not Provided | 2026-09-09 | 2026-09-10 |
| CVE-2021-28131 json | Impala sessions use a 16 byte secret to verify that the session is not being hijacked by another user. However, these secrets... | 7.5 - HIGH | 2021-07-22 | 2023-11-07 |
| CVE-2019-10084 json | In Apache Impala 2.7.0 to 3.2.0, an authenticated user with access to the IDs of active Impala queries or sessions can intera... | 7.5 - HIGH | 2019-11-05 | 2023-11-07 |
| CVE-2018-11792 json | In Apache Impala before 3.0.1, ALTER TABLE/VIEW RENAME required ALTER on the old table. This may pose a potential security ri... | 9.8 - CRITICAL | 2018-10-24 | 2023-11-07 |
| CVE-2018-11785 json | Missing authorization check in Apache Impala before 3.0.1 allows a Kerberos-authenticated but unauthorized user to inject ran... | 6.5 - MEDIUM | 2018-10-24 | 2023-11-07 |
| CVE-2017-9792 json | In Apache Impala (incubating) before 2.10.0, a malicious user with "ALTER" permissions on an Impala table can access any othe... | 6.5 - MEDIUM | 2017-10-04 | 2023-11-07 |
| CVE-2017-5652 json | Not Provided | 2017-07-10 | 2025-04-20 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Impala | 3.2.0 | |||
| Application | Apache | Impala | 3.1.0 | |||
| Application | Apache | Impala | 3.0.1 | |||
| Application | Apache | Impala | 3.0.0 | |||
| Application | Apache | Impala | 2.9.0 | |||
| Application | Apache | Impala | 2.8.0 | |||
| Application | Apache | Impala | 2.7.0 | |||
| Application | Apache | Impala | 2.12.0 | |||
| Application | Apache | Impala | 2.11.0 | |||
| Application | Apache | Impala | 2.10.0 |