Description
The YARN NodeManager in Apache Hadoop 2.7.3 and 2.7.4 can leak the password for credential store provider used by the NodeManager to YARN Applications.
Remediation
References
https://lists.apache.org/thread.html/773c93c2d8a6a52bbe97610c2b1c2ad205b970e1b8c04fb5b2fccad6%40%3Cgeneral.hadoop.apache.org%3E
Related Vulnerabilities
CVE-2020-26291 Vulnerability in maven package org.webjars.bower:urijs
CVE-2016-3720 Vulnerability in maven package com.fasterxml.jackson.dataformat:jackson-dataformat-xml
CVE-2020-24703 Vulnerability in maven package org.wso2.carbon:org.wso2.carbon.ui
CVE-2023-22602 Vulnerability in maven package org.apache.shiro:shiro-spring-boot-starter
CVE-2023-30548 Vulnerability in npm package gatsby-plugin-sharp