Impact
The vulnerability is a classic path traversal (CWE‑23) within the 'trusted_jar_paths' configuration of Apache Impala 4.5.2. By providing a relative path that matches a suffix of a trusted URI, an attacker can trick Impala into loading a JAR file that has been uploaded to an unauthorized location through DDL statements such as CREATE DATA SOURCE or CREATE TABLE. Once loaded, the JAR’s code runs with the permissions of the Impala service, giving the attacker remote code execution capabilities on the host where Impala is running.
Affected Systems
Apache Software Foundation’s Apache Impala version 4.5.2 is affected. The issue only manifests when the Impala administrator has configured a non‑empty 'trusted_jar_paths' value. No other Impala versions are listed as vulnerable.
Risk and Exploitability
The exploit requires an attacker to have privileges to execute DDL statements that place a malicious JAR under a trusted path. The vulnerability is not listed in CISA’s KEV catalog, and no EPSS score is available. However, because the flaw can lead to full control of the Impala host and is present in a public configuration option, the risk is considered high. If exploited, an attacker can run arbitrary code within the Impala process, potentially compromising the underlying system and any data it processes.
OpenCVE Enrichment