Lucene search

K
zdtCloudera1337DAY-ID-28113
HistoryJul 11, 2017 - 12:00 a.m.

Apache Impala 2.8.0 Authentication Bypass Vulnerability

2017-07-1100:00:00
Cloudera
0day.today
22

EPSS

0.002

Percentile

51.4%

Apache Impala versions 2.7.0 through 2.8.0 suffers from an information disclosure vulnerability. It was noticed that a malicious process impersonating an Impala daemon could cause Impala daemons to skip authentication checks when Kerberos is enabled (but TLS is not). If the malicious server responds with ‘COMPLETE’ before the SASL handshake has completed, the client will consider the handshake as completed even though no exchange of credentials has happened.

CVE-2017-5640 Apache Impala (incubating) Information Disclosure

Versions Affected:
Apache Impala (incubating) 2.7.0 to 2.8.0

Description:
It was noticed that a malicious process impersonating an Impala daemon
could cause Impala daemons to skip authentication checks when Kerberos
is enabled (but TLS is not). If the malicious server responds with
aCOMPLETEa before the SASL handshake has completed, the client will
consider the handshake as completed even though no exchange of
credentials has happened.

Mitigation:
Users of the affected versions should apply the following mitigation:
Upgrade to Apache Impala (incubating) 2.9.0

Credit:
This issue was identified by the Cloudera Security team.

References:
https://issues.apache.org/jira/browse/IMPALA-5005

#  0day.today [2018-03-31]  #

EPSS

0.002

Percentile

51.4%

Related for 1337DAY-ID-28113