Vulnerabilities > Apache > Impala > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-10-24 CVE-2018-11785 Missing Authorization vulnerability in Apache Impala
Missing authorization check in Apache Impala before 3.0.1 allows a Kerberos-authenticated but unauthorized user to inject random data into a running query, leading to wrong results for a query.
network
low complexity
apache CWE-862
6.5
2017-10-04 CVE-2017-9792 Incorrect Permission Assignment for Critical Resource vulnerability in Apache Impala 2.8.0/2.9.0
In Apache Impala (incubating) before 2.10.0, a malicious user with "ALTER" permissions on an Impala table can access any other Kudu table data by altering the table properties to make it "external" and then changing the underlying table mapping to point to other Kudu tables.
network
low complexity
apache CWE-732
6.5