In Apache Impala before 3.0.1, ALTER TABLE/VIEW RENAME required ALTER on the old table. This may pose a potential security risk, such as having ALTER on a table and ALL on a particular database allows a user to move the table to a database with ALL, which will automatically grant that user with ALL privilege on that table due to the privilege inherited from the database.
Advisories
Source ID Title
EUVD EUVD EUVD-2018-3791 In Apache Impala before 3.0.1, ALTER TABLE/VIEW RENAME required ALTER on the old table. This may pose a potential security risk, such as having ALTER on a table and ALL on a particular database allows a user to move the table to a database with ALL, which will automatically grant that user with ALL privilege on that table due to the privilege inherited from the database.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2024-09-16T19:52:28.202Z

Reserved: 2018-06-05T00:00:00

Link: CVE-2018-11792

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-10-24T20:29:00.367

Modified: 2024-11-21T03:44:02.830

Link: CVE-2018-11792

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.