Cloudera JDBC Connector for Hive and Impala JNDI Injection Vulnerability Allowing Remote Code Execution
Vulnerability
A JNDI injection vulnerability has been identified in Cloudera JDBC Connector for Hive versions prior to 2.6.26 and in JDBC Connector for Impala versions prior to 2.6.35. This vulnerability allows attackers to inject malicious parameters into the JDBC URL, which the JDBC Driver may then use to connect to the database. The injection can be exploited through the JDBC connection property 'krbJAASFile', related to the Java Authentication and Authorization Service (JAAS). Improper use of untrusted parameters in 'krbJAASFile' and/or remote host can trigger JNDI injection, potentially leading to remote code execution.
Impact
Exploitation of this vulnerability could result in remote code execution on the server where the affected JDBC connector is used.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
