CVE-2024-54660: Command Injection
A JNDI injection issue was discovered in Cloudera JDBC Connector for Hive before 2.6.26 and JDBC Connector for Impala before 2.6.35. Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process when the JDBC Driver uses this URL to connect to the database. This could lead to remote code execution. JNDI injection is possible via the JDBC connection property krbJAASFile for the Java Authentication and Authorization Service (JAAS). Using untrusted parameters in the krbJAASFile and/or remote host can trigger JNDI injection in the JDBC URL through the krbJAASFile.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-54660?
CVE-2024-54660 is classified as a high severity vulnerability due to the potential for JNDI injection attacks.
How do I fix CVE-2024-54660?
To fix CVE-2024-54660, upgrade to Cloudera JDBC Connector for Hive version 2.6.26 or later, or Cloudera JDBC Connector for Impala version 2.6.35 or later.
Which versions are vulnerable to CVE-2024-54660?
CVE-2024-54660 affects Cloudera JDBC Connector for Hive versions prior to 2.6.26 and Cloudera JDBC Connector for Impala versions prior to 2.6.35.
What impact does CVE-2024-54660 have on my system?
The impact of CVE-2024-54660 includes potential unauthorized access to resources via JNDI injection, compromising database integrity and security.
Is there a workaround for CVE-2024-54660?
There are currently no documented workarounds for CVE-2024-54660; upgrading to the secure versions is strongly recommended.