Credential Store Password Leak in Apache Hadoop YARN NodeManager
CVE-2017-15718
9.8CRITICAL
What is CVE-2017-15718?
The YARN NodeManager component of Apache Hadoop versions 2.7.3 and 2.7.4 is susceptible to a vulnerability that allows the password for the credential store provider to be exposed to YARN applications. This issue arises due to improper management of sensitive information within the NodeManager, potentially enabling unauthorized access to critical credentials.
Affected Version(s)
Apache Hadoop 2.7.3 to 2.7.4