Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2021-28131
Apache Impala vulnerability analysis and mitigation

Overview

Apache Impala deployments with Apache Sentry or Apache Ranger authorization enabled were found to be vulnerable to privilege escalation through session hijacking. The vulnerability (CVE-2021-28131) was disclosed on July 22, 2021, affecting Impala versions prior to 4.0. The issue stems from Impala sessions using 16-byte secrets for session verification that were exposed in system logs (OSS Security).

Technical details

The vulnerability involves Impala's session management system where 16-byte secrets used to verify session authenticity were being logged in plaintext. These secrets are meant to prevent session hijacking, but their exposure in logs undermines this security measure. The vulnerability requires a high degree of technical sophistication and authenticated access to exploit (OSS Security).

Impact

The vulnerability enables authenticated attackers with access to logs to hijack sessions from other authenticated users, potentially executing statements with privileges they don't normally possess. Additionally, deployments with audit logging enabled may be vulnerable to incorrect audit logging, as attackers could perform actions that would be logged under a different user's identity (OSS Security).

Exploitability

Exploitation requires an attacker to be an authenticated user with access to Impala system logs. The attacker must possess high technical sophistication to construct special requests using the exposed session secrets. The attack is only possible in environments where Apache Sentry or Apache Ranger authorization is enabled (OSS Security).

Mitigation and workarounds

The primary mitigation is upgrading to Impala version 4.0 or later, which includes the fix for IMPALA-10600. Alternative mitigations include restricting access to logs containing secrets, limiting Impala deployment access to trusted users only, and implementing log redaction techniques to remove secrets from logs (OSS Security).

Additional resources


SourceThis report was generated using AI

Related Apache Impala vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-56207CRITICAL9.8
  • Apache Impala logoApache Impala
  • impala
NoYesSep 09, 2026
CVE-2026-57866HIGH8.8
  • Apache Impala logoApache Impala
  • impala
NoNoSep 09, 2026
CVE-2026-65181HIGH8.1
  • Apache Impala logoApache Impala
  • cpe:2.3:a:apache:impala
NoYesSep 09, 2026
CVE-2021-28131HIGH7.5
  • Apache Impala logoApache Impala
  • impala
NoYesJul 22, 2021
CVE-2026-54048MEDIUM5.3
  • Apache Impala logoApache Impala
  • impala
NoYesSep 09, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management