⚠ Exploited in the wild
Exploitation observed in the wild. Not yet on CISA KEV.

CVE-2017-15718

Severity
9.8CRITICAL
EPSS
1.3%
top 20.01%
CISA KEV
Not in KEV
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedJan 24
Latest updateDec 21

Description

The YARN NodeManager in Apache Hadoop 2.7.3 and 2.7.4 can leak the password for credential store provider used by the NodeManager to YARN Applications.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

Mavenorg.apache.hadoop:hadoop-main2.7.32.7.5
NVDapache/hadoop2.7.3, 2.7.4+1

🔴Vulnerability Details

4
GHSA
Exposure of Sensitive Information in Hadoop2018-12-21
OSV
Exposure of Sensitive Information in Hadoop2018-12-21
CVEList
CVE-2017-15718: The YARN NodeManager in Apache Hadoop 22018-01-24
VulnCheck
Apache Hadoop 2.7.3 and 2.7.4 YARN NodeManager Password Disclosure2017

📋Vendor Advisories

1
Apache
Apache hadoop: CVE-2017-15718

💬Community

2
Bugzilla
CVE-2017-15718 hadoop: YARN NodeManager can leak the password for the credential store provider [fedora-all]2018-01-29
Bugzilla
CVE-2017-15718 hadoop: YARN NodeManager can leak the password for the credential store provider2018-01-29