CVE-2017-5640

Severity
9.8CRITICAL
EPSS
1.3%
top 20.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 10
Latest updateMay 17

Description

It was noticed that a malicious process impersonating an Impala daemon in Apache Impala (incubating) 2.7.0 to 2.8.0 could cause Impala daemons to skip authentication checks when Kerberos is enabled (but TLS is not). If the malicious server responds with 'COMPLETE' before the SASL handshake has completed, the client will consider the handshake as completed even though no exchange of credentials has happened.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

NVDapache/impala2.7.0, 2.8.0+1
CVEListV5apache_software_foundation/apache_impala2.7.0 to 2.8.0 incubating

🔴Vulnerability Details

2
GHSA
GHSA-pprr-66x6-xjr8: It was noticed that a malicious process impersonating an Impala daemon in Apache Impala (incubating) 22022-05-17
CVEList
CVE-2017-5640: It was noticed that a malicious process impersonating an Impala daemon in Apache Impala (incubating) 22017-07-10