Impala
Vendor:
First CVE: Jul 10, 2017 · Active for 9 years
7
Total CVEs
More Total CVEs than 83% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
7.9
Avg CVSS
Higher Avg CVSS than 68% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Impala over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 10, 2017
9 years ago
Most Recent CVE
Jul 22, 2021
1,828 days ago
CVE Severity & Scoring
Impala7 CVEs
29%
43%
29%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (71.4%)
High2 (28.6%)
Unknown0 (0.0%)
User Interaction
None7 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low4 (57.1%)
High0 (0.0%)
None3 (42.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-5640CRITICAL It was noticed that a malicious process impersonating an Impala daemon in Apache Impala (incubating) 2.7.0 to 2.8.0 could cause Impala daemons to skip authentication checks when Ke | Jul 10, 2017 | 9.8 | 32 | NO | NO |
CVE-2018-11792CRITICAL In Apache Impala before 3.0.1, ALTER TABLE/VIEW RENAME required ALTER on the old table. This may pose a potential security risk, such as having ALTER on a table and ALL on a partic | Oct 24, 2018 | 9.8 | 31 | NO | NO |
CVE-2021-28131HIGH Impala sessions use a 16 byte secret to verify that the session is not being hijacked by another user. However, these secrets appear in the Impala logs, therefore Impala users with | Jul 22, 2021 | 7.5 | 26 | NO | NO |
CVE-2017-5652HIGH During a routine security analysis, it was found that one of the ports in Apache Impala (incubating) 2.7.0 to 2.8.0 sent data in plaintext even when the cluster was configured to u | Jul 10, 2017 | 7.5 | 26 | NO | NO |
CVE-2019-10084HIGH In Apache Impala 2.7.0 to 3.2.0, an authenticated user with access to the IDs of active Impala queries or sessions can interact with those sessions or queries via a specially-const | Nov 5, 2019 | 7.5 | 22 | NO | NO |
CVE-2018-11785MEDIUM Missing authorization check in Apache Impala before 3.0.1 allows a Kerberos-authenticated but unauthorized user to inject random data into a running query, leading to wrong results | Oct 24, 2018 | 6.5 | 22 | NO | NO |
CVE-2017-9792MEDIUM In Apache Impala (incubating) before 2.10.0, a malicious user with "ALTER" permissions on an Impala table can access any other Kudu table data by altering the table properties to m | Oct 4, 2017 | 6.5 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (7 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (7 CVEs).
Media Mentions
Signals from CVEs in this product scope (7 CVEs).
Top CNAs Publishing CVEs For Impala
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.9.0 | 1 | 6.5 | 1.6% | 0 | 0 |
| 2.8.0 | 3 | 7.9 | 1.9% | 0 | 0 |
| 2.7.0 | 2 | 8.7 | 2.0% | 0 | 0 |