
VulniPulse@vulnipulse
CVE advisory (UNKNOWN): CVE-2026-93684 - apache: Apache Impala: Stored XSS in Impala query plans. https://vulnipulse.com/advisories/apache-cve-2026-93684 #CVE #CyberSecurity #Apache #ApacheImpala
0000014
6 followersView on X
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
An SQL user using Impala up to and including version 4.5.2 with only SELECT permission can put JavaScript in a table alias and make it run in another user's browser when that user opens the query plan in Impala's Web UI. This is stored XSS (CWE-79). Users are recommended to upgrade to version 4.5.3.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

CVE advisory (UNKNOWN): CVE-2026-93684 - apache: Apache Impala: Stored XSS in Impala query plans. https://vulnipulse.com/advisories/apache-cve-2026-93684 #CVE #CyberSecurity #Apache #ApacheImpala