Local User Information Exposure in Apache Ambari
CVE-2016-4976
5.5MEDIUM
What is CVE-2016-4976?
Apache Ambari versions prior to 2.4.0 reveal KDC administrator passwords in the command line of the kadmin tool. This flaw enables local users to extract sensitive information through process listings, potentially compromising authentication mechanisms. Proper handling and sanitization of command line input are crucial to mitigate this vulnerability.