First published: Wed Oct 24 2018(Updated: )
Missing authorization check in Apache Impala before 3.0.1 allows a Kerberos-authenticated but unauthorized user to inject random data into a running query, leading to wrong results for a query.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Impala | <3.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-11785 is rated as a moderate severity vulnerability.
To fix CVE-2018-11785, upgrade Apache Impala to version 3.0.1 or later.
CVE-2018-11785 allows unauthorized users to inject random data into queries, leading to incorrect query results.
Apache Impala versions prior to 3.0.1 are affected by CVE-2018-11785.
CVE-2018-11785 is a software vulnerability affecting Apache Impala.