Vulnerability Description
The YARN NodeManager in Apache Hadoop 2.7.3 and 2.7.4 can leak the password for credential store provider used by the NodeManager to YARN Applications.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Hadoop | 2.7.3 |
References
- https://lists.apache.org/thread.html/773c93c2d8a6a52bbe97610c2b1c2ad205b970e1b8c
- https://lists.apache.org/thread.html/773c93c2d8a6a52bbe97610c2b1c2ad205b970e1b8c
FAQ
What is CVE-2017-15718?
CVE-2017-15718 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The YARN NodeManager in Apache Hadoop 2.7.3 and 2.7.4 can leak the password for credential store provider used by the NodeManager to YARN Applications.
How severe is CVE-2017-15718?
CVE-2017-15718 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2017-15718?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Hadoop.