CVE-2018-11792
24.10.2018, 20:29
In Apache Impala before 3.0.1, ALTER TABLE/VIEW RENAME required ALTER on the old table. This may pose a potential security risk, such as having ALTER on a table and ALL on a particular database allows a user to move the table to a database with ALL, which will automatically grant that user with ALL privilege on that table due to the privilege inherited from the database.Enginsight
Vendor | Product | Version |
---|---|---|
apache | impala | 𝑥 < 3.0.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References