CVE Database
/

CVE-2018-11792

Back to search

CVE-2018-11792

Published: Oct 24, 2018

Modified: Sep 16, 2024

PUBLISHED

Description

In Apache Impala before 3.0.1, ALTER TABLE/VIEW RENAME required ALTER on the old table. This may pose a potential security risk, such as having ALTER on a table and ALL on a particular database allows a user to move the table to a database with ALL, which will automatically grant that user with ALL privilege on that table due to the privilege inherited from the database.

VendorProductVersions

Apache Software Foundation

Apache Impala

affected
Apache Impala 3.0.0

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now