Signature of Bearer token is not verified in last step of...
Critical severity
Unreviewed
Published
Sep 9, 2026
to the GitHub Advisory Database
•
Updated Sep 25, 2026
Description
Published by the National Vulnerability Database
Sep 9, 2026
Published to the GitHub Advisory Database
Sep 9, 2026
Last updated
Sep 25, 2026
Signature of Bearer token is not verified in last step of SAML2 authentication for Impala's hs2-http interface, allowing altering user name and acting as another user.
This issue affects Apache Impala: >=4.0.0.
Users are recommended to upgrade to version 4.5.2, which fixes this issue.
References