Impact
The vulnerability arises from an improper implementation of JWT/OAuth authentication in Apache Impala executors up to version 4.5.2, which fails to validate bearer token signatures. As a result, any token that is syntactically valid is accepted, allowing an attacker to bypass authentication and access resources served by the executor’s webserver. This leads to unauthorized disclosure of data or code hosted by the executor and can be exploited for further compromise.
Affected Systems
Vendors affected include the Apache Software Foundation’s Impala product. All releases through version 4.5.2 are impacted; versions 4.5.3 and later contain the fix. The weakness is limited to executors configured to use JWT/OAuth authentication.
Risk and Exploitability
Although EPSS data is not available, the vulnerability is not listed in CISA's KEV catalog, the lack of signature validation represents a high severity flaw by CWE‑303 standards. Exploitation requires a valid JWT structure but not a valid signature, which can be fabricated by an attacker with network access to the executor. The attack vector is likely remote, leveraging any channel that allows sending bearer tokens to the webserver. Given the absence of publicly disclosed exploits, actual exploitation probability may be moderate, but the potential impact warrants immediate remedial action.
OpenCVE Enrichment