Impact
The vulnerability exists in Apache Impala's hs2-http SAML 2.0 authentication system, where the signature of the Bearer token is not verified during the last step of authentication. This flaw allows an attacker to alter the user name claimed by a token and act as a different user, effectively bypassing authentication controls and enabling identity spoofing.
Affected Systems
All installations of Apache Impala version 4.0.0 and later are affected. The issue has been fixed in version 4.5.2; users are advised to upgrade to at least that version.
Risk and Exploitability
The CVSS score is not specified, and the EPSS score is unavailable, indicating that no published exploitation probability is known at this time. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed exploits. Nonetheless, an attacker with the ability to forge a Bearer token could manipulate authentication without detection, granting unauthorized access to privileged resources. Remediation requires applying the vendor patch or upgrading to the fixed version.
OpenCVE Enrichment