CVE-2017-15718

CRITICAL EXPLOITED IN THE WILD

Apache Hadoop <2.7.5 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2017-15718 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io).

Description

The YARN NodeManager in Apache Hadoop 2.7.3 and 2.7.4 can leak the password for credential store provider used by the NodeManager to YARN Applications.

Scores

CVSS v3 9.8
EPSS 0.0159
EPSS Percentile 81.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2020-01-16
InTheWild.io 2024-05-17
Status published
Products (3)
apache/hadoop 2.7.3
apache/hadoop 2.7.4
org.apache.hadoop/hadoop-main 2.7.3 - 2.7.5Maven
Published Jan 24, 2018
Tracked Since Feb 18, 2026