Impact
Server side request forgery exists in 4.4.x and 4.5.x. Authenticated users who have permission to execute the ai_generate_text() function can supply arbitrary URLs; Impala will perform outbound requests to those URLs and can retrieve data provided by the credential providers configured in the hadoop.security.credential.provider.path property of core‑site.xml. The secret’s key must be known to the user in order to exfiltrate the credential value. The result is that sensitive credentials stored in Hadoop credential providers can be exfiltrated through the Impala server, compromising confidentiality.
Affected Systems
The vulnerability affects Apache Impala database engine versions 4.4.x and 4.5.x. An attacker must authenticate to Impala and possess the privilege to run ai_generate_text() in order to exploit the flaw. The configuration setting hadoop.security.credential.provider.path in core‑site.xml must specify credential providers for the exfiltration to succeed.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity risk. The EPSS score of <1% suggests the probability of exploitation remains low, flaw is not listed in the CISA KEV catalog, indicating no known public exploits at execute ai_generate_text() can use the SSRF flaw to exfiltrate secrets from Hadoop credential providers when the credential key is known, potentially compromising sensitive credentials. The flaw is present in both 4.4.x and 4.5.x builds of Impala. Although the attack surface is limited to users inside the Impala environment, the confidentiality impact remains significant, and the availability of a high‑severity score warrants prompt remediation.
OpenCVE Enrichment