Executive brief
Apache Polaris is a data cataloging service that manages Apache Iceberg table metadata stored in cloud storage. A vulnerability allows authenticated users with table modification permissions to redirect metadata writes to attacker-controlled storage locations, bypassing security validation checks. This could expose sensitive table metadata and data to unauthorized access or modification, particularly if cloud credentials are later issued for the poisoned location.
Technical details
The vulnerability is an improper input validation flaw (CWE-20) in Apache Polaris's handling of the `write.metadata.path` table property. When a user modifies only this property via ALTER TABLE settings (not row-level DML), Polaris skips its intended location-validation commit-time check. This allows an authenticated attacker with table modification privileges to cause Polaris to write table metadata to an arbitrary storage location before validation occurs. In configurations where `polaris.config.allow.unstructured.table.location=true` and `allowedLocations` is broad, the attacker can target paths outside the intended table directory. If subsequent validation also accepts the poisoned location, Polaris persists it in table state; later credential-vending APIs may then issue temporary cloud storage access for that location without revalidation. The practical impact extends beyond credential vending—Polaris itself performs the unsafe metadata write to the unchecked location. The defect exists regardless of the unstructured location flag, though the flag controls whether the metadata path is later persisted. Affected versions 0.9.0 through 1.4.0 are patched in version 1.4.1.
Affected products
- Apache Polaris 0.9.0 through 1.4.0
Timeline
- 2026-05-04: disclosed
- 2026-05-04: patched: Version 1.4.1 patches the vulnerability