Description
The YARN NodeManager in Apache Hadoop 2.6.x before 2.6.5 and 2.7.x before 2.7.3 can leak the password for credential store provider used by the NodeManager to YARN Applications.
Remediation
References
http://mail-archives.apache.org/mod_mbox/hadoop-general/201701.mbox/%3C0ed32746-5a53-9051-5877-2b1abd88beb6%40apache.org%3E
http://www.securityfocus.com/bid/95335
Related Vulnerabilities
CVE-2022-36917 Vulnerability in maven package org.jenkins-ci.plugins:google-cloud-backup
CVE-2021-34797 Vulnerability in maven package org.apache.geode:geode-core
CVE-2021-21345 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2023-34603 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-parent
CVE-2022-36025 Vulnerability in maven package org.hyperledger.besu:evm