
Cloud Vulnerability DB
A community-led vulnerabilities database
Apache Impala deployments with Apache Sentry or Apache Ranger authorization enabled were found to be vulnerable to privilege escalation through session hijacking. The vulnerability (CVE-2021-28131) was disclosed on July 22, 2021, affecting Impala versions prior to 4.0. The issue stems from Impala sessions using 16-byte secrets for session verification that were exposed in system logs (OSS Security).
The vulnerability involves Impala's session management system where 16-byte secrets used to verify session authenticity were being logged in plaintext. These secrets are meant to prevent session hijacking, but their exposure in logs undermines this security measure. The vulnerability requires a high degree of technical sophistication and authenticated access to exploit (OSS Security).
The vulnerability enables authenticated attackers with access to logs to hijack sessions from other authenticated users, potentially executing statements with privileges they don't normally possess. Additionally, deployments with audit logging enabled may be vulnerable to incorrect audit logging, as attackers could perform actions that would be logged under a different user's identity (OSS Security).
Exploitation requires an attacker to be an authenticated user with access to Impala system logs. The attacker must possess high technical sophistication to construct special requests using the exposed session secrets. The attack is only possible in environments where Apache Sentry or Apache Ranger authorization is enabled (OSS Security).
The primary mitigation is upgrading to Impala version 4.0 or later, which includes the fix for IMPALA-10600. Alternative mitigations include restricting access to logs containing secrets, limiting Impala deployment access to trusted users only, and implementing log redaction techniques to remove secrets from logs (OSS Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."