CVE-2016-3086: Infoleak
The YARN NodeManager in Apache Hadoop 2.6.x before 2.6.5 and 2.7.x before 2.7.3 can leak the password for credential store provider used by the NodeManager to YARN Applications.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-3086?
CVE-2016-3086 has been classified as a medium severity vulnerability due to the potential exposure of sensitive credentials.
How do I fix CVE-2016-3086?
To fix CVE-2016-3086, upgrade Apache Hadoop to version 2.6.5 or later for the 2.6.x branch, or version 2.7.3 or later for the 2.7.x branch.
What is the impact of CVE-2016-3086?
The impact of CVE-2016-3086 is that it can lead to the leakage of passwords from the credential store provider used by the NodeManager.
Which versions of Apache Hadoop are affected by CVE-2016-3086?
CVE-2016-3086 affects Apache Hadoop versions 2.6.0 to 2.6.4 and 2.7.0 to 2.7.2.
Is CVE-2016-3086 a local or remote vulnerability?
CVE-2016-3086 is primarily a local vulnerability, as it requires access to the YARN applications running on the NodeManager.