JNDI Injection Vulnerability in Cloudera JDBC Connector for Hive and Impala
CVE-2024-54660
8.7HIGH
What is CVE-2024-54660?
A JNDI injection vulnerability allows attackers to manipulate JDBC URL parameters, exploiting the JDBC Driver's connection process. Specifically, untrusted input in the krbJAASFile property can initiate JNDI injection, potentially leading to remote code execution. This highlights the risks associated with improper handling of JDBC connection properties in Cloudera's JDBC Connector for Hive and Impala, underscoring the critical importance of secure coding practices.