cbcvebase.
CVE-2017-15718
published 2018-01-24

CVE-2017-15718: The YARN NodeManager in Apache Hadoop 2.7.3 and 2.7.4 can leak the password for credential store provider used by the NodeManager to YARN Applications.

PriorityP275critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
3.57%
88.0th percentile
The YARN NodeManager in Apache Hadoop 2.7.3 and 2.7.4 can leak the password for credential store provider used by the NodeManager to YARN Applications.

Affected

4 ranges
VendorProductVersion rangeFixed in
apachehadoop
apachehadoop
apachehadoop
apache_software_foundationapache_hadoop

Detection & IOCsextracted from sources · hover to see the quote

  • YARN NodeManager leaks the credential store provider password to YARN Applications/Containers — monitor NodeManager logs and environment variables passed to launched Containers for the presence of credential store (jceks) passwords
  • Audit file permissions on jceks credential store files on NodeManager hosts — world-readable jceks files are an indicator of exposure under this CVE
  • This CVE is an incomplete fix for CVE-2016-3086 — correlate findings with that prior CVE when triaging YARN NodeManager credential leakage incidents
  • ·Only affects Apache Hadoop versions 2.7.3 and 2.7.4; the vulnerability is limited to deployments using the CredentialProvider feature to encrypt NodeManager config passwords
  • ·The encryption password for the credential store is what leaks — the other underlying passwords stored within the credential store are not directly exposed via this vulnerability

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vulncheck9.8CRITICAL
vendor_apache9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.