CVE-2017-5640
CRITICALApache Impala 2.7.0-2.8.0 - Improper Authentication via Early SASL Handshake Completion
Title source: llmDescription
It was noticed that a malicious process impersonating an Impala daemon in Apache Impala (incubating) 2.7.0 to 2.8.0 could cause Impala daemons to skip authentication checks when Kerberos is enabled (but TLS is not). If the malicious server responds with 'COMPLETE' before the SASL handshake has completed, the client will consider the handshake as completed even though no exchange of credentials has happened.
References (2)
Core 2
Core References
Mailing List mailing-list
x_refsource_mlist
https://lists.apache.org/thread.html/c02e83aa46c90b7cbc87dd649cf8f9b73e11053eddea9144a397da53%40%3Cdev.impala.apache.org%3E
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/99508
Scores
CVSS v3
9.8
EPSS
0.0130
EPSS Percentile
79.9%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-287
Status
published
Products (3)
apache/impala
2.7.0
apache/impala
2.8.0
Apache Software Foundation/Apache Impala
2.7.0 to 2.8.0 incubating
Published
Jul 10, 2017
Tracked Since
Feb 18, 2026