Description
The YARN NodeManager in Apache Hadoop 2.7.3 and 2.7.4 can leak the password for credential store provider used by the NodeManager to YARN Applications.
Remediation
References
https://lists.apache.org/thread.html/773c93c2d8a6a52bbe97610c2b1c2ad205b970e1b8c04fb5b2fccad6%40%3Cgeneral.hadoop.apache.org%3E
Related Vulnerabilities
CVE-2019-19771 Vulnerability in npm package crpyto-js
CVE-2017-3160 Vulnerability in npm package cordova-android
CVE-2017-7680 Vulnerability in maven package org.apache.openmeetings:openmeetings-server
CVE-2019-10356 Vulnerability in maven package org.jenkins-ci.plugins:script-security
CVE-2015-1926 Vulnerability in maven package org.apache.portals.pluto:portletv3annotateddemo