CVE-2017-15718
published 2018-01-24CVE-2017-15718: The YARN NodeManager in Apache Hadoop 2.7.3 and 2.7.4 can leak the password for credential store provider used by the NodeManager to YARN Applications.
PriorityP275critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
3.57%
88.0th percentile
The YARN NodeManager in Apache Hadoop 2.7.3 and 2.7.4 can leak the password for credential store provider used by the NodeManager to YARN Applications.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache_software_foundation | apache_hadoop | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →YARN NodeManager leaks the credential store provider password to YARN Applications/Containers — monitor NodeManager logs and environment variables passed to launched Containers for the presence of credential store (jceks) passwords ↗
- →Audit file permissions on jceks credential store files on NodeManager hosts — world-readable jceks files are an indicator of exposure under this CVE ↗
- →This CVE is an incomplete fix for CVE-2016-3086 — correlate findings with that prior CVE when triaging YARN NodeManager credential leakage incidents ↗
- ·Only affects Apache Hadoop versions 2.7.3 and 2.7.4; the vulnerability is limited to deployments using the CredentialProvider feature to encrypt NodeManager config passwords ↗
- ·The encryption password for the credential store is what leaks — the other underlying passwords stored within the credential store are not directly exposed via this vulnerability ↗
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vulncheck9.8CRITICAL
vendor_apache9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Exposure of Sensitive Information in Hadoop
ghsa·2018-12-21
CVE-2017-15718 [CRITICAL] CWE-200 Exposure of Sensitive Information in Hadoop
Exposure of Sensitive Information in Hadoop
The YARN NodeManager in Apache Hadoop 2.7.3 and 2.7.4 can leak the password for credential store provider used by the NodeManager to YARN Applications.
OSV
Exposure of Sensitive Information in Hadoop
osv·2018-12-21
CVE-2017-15718 [CRITICAL] Exposure of Sensitive Information in Hadoop
Exposure of Sensitive Information in Hadoop
The YARN NodeManager in Apache Hadoop 2.7.3 and 2.7.4 can leak the password for credential store provider used by the NodeManager to YARN Applications.
VulnCheck
Apache Hadoop 2.7.3 and 2.7.4 YARN NodeManager Password Disclosure
vulncheck·2017·CVSS 9.8
CVE-2017-15718 [CRITICAL] Apache Hadoop 2.7.3 and 2.7.4 YARN NodeManager Password Disclosure
Apache Hadoop 2.7.3 and 2.7.4 YARN NodeManager Password Disclosure
The YARN NodeManager in Apache Hadoop 2.7.3 and 2.7.4 can leak the password for credential store provider used by the NodeManager to YARN Applications.
Affected: Apache hadoop
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://www.alibabacloud.com/blog/new-outbreak-of-h2miner-worms-exploiting-redis-rce-detected_595743; https://1665891.fs1.hubspotusercontent-na1.net/hubfs/1665891/Threat%20reports/AquaSecurity_Kinsing_Demystified_Technical_Guide.pdf
Apache
Apache hadoop: CVE-2017-15718
vendor_apache·CVSS 9.8
CVE-2017-15718 [CRITICAL] Apache hadoop: CVE-2017-15718
Apache hadoop: CVE-2017-15718
In Apache Hadoop 2.7.3 and 2.7.4, the security fix for CVE-2016-3086 is incomplete. The YARN NodeManager can leak the password for credential store provider used by the NodeManager to YARN Applications. If you use the CredentialProvider feature to encrypt passwords used in NodeManager configs, it may be possible for any Container launched by that NodeManager to gain access to the encryption password. The other passwords themselves are not directly exposed.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-15718 hadoop: YARN NodeManager can leak the password for the credential store provider [fedora-all]
bugzilla·2018-01-29·CVSS 9.8
CVE-2017-15718 [CRITICAL] CVE-2017-15718 hadoop: YARN NodeManager can leak the password for the credential store provider [fedora-all]
CVE-2017-15718 hadoop: YARN NodeManager can leak the password for the credential store provider [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affe
Bugzilla
CVE-2017-15718 hadoop: YARN NodeManager can leak the password for the credential store provider
bugzilla·2018-01-29·CVSS 9.8
CVE-2017-15718 [CRITICAL] CVE-2017-15718 hadoop: YARN NodeManager can leak the password for the credential store provider
CVE-2017-15718 hadoop: YARN NodeManager can leak the password for the credential store provider
The YARN NodeManager in Apache Hadoop 2.7.3 and 2.7.4 can leak the password for credential store provider used by the NodeManager to YARN Applications.
External References:
https://lists.apache.org/thread.html/773c93c2d8a6a52bbe97610c2b1c2ad205b970e1b8c04fb5b2fccad6@%3Cgeneral.hadoop.apache.org%3E
Discussion:
Created hadoop tracking bugs for this issue:
Affects: fedora-all [bug 1539513]
---
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.
2018-01-24
Published
Exploited in the wild