CVE-2016-3086

Description

The YARN NodeManager in Apache Hadoop 2.6.x before 2.6.5 and 2.7.x before 2.7.3 can leak the password for credential store provider used by the NodeManager to YARN Applications.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.428

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2016-3086 are fixed in Apache-hadoop-yarn-server-nodemanager 2.6.5Windows
Vulnerabilities CVE-2016-3086 are fixed in Apache-hadoop-yarn-server-nodemanager 2.7.3Windows
Vulnerabilities CVE-2016-3086 are fixed in Apache-hadoop-yarn-server-nodemanager for Linux 2.6.5Linux
Vulnerabilities CVE-2016-3086 are fixed in Apache-hadoop-yarn-server-nodemanager for Linux 2.7.3Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234