VYPR
Critical severity9.8NVD Advisory· Published Jan 24, 2018· Updated Jun 17, 2026

CVE-2017-15718

CVE-2017-15718

Description

The YARN NodeManager in Apache Hadoop 2.7.3 and 2.7.4 can leak the password for credential store provider used by the NodeManager to YARN Applications.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.hadoop:hadoop-mainMaven
>= 2.7.3, < 2.7.52.7.5

Affected products

4
  • Apache Software Foundation/Apache Hadoopv5
    Range: 2.7.3 to 2.7.4
  • ghsa-coords
    Range: >= 2.7.3, < 2.7.5
  • Apache/Hadoop2 versions
    cpe:2.3:a:apache:hadoop:2.7.3:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:apache:hadoop:2.7.3:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:hadoop:2.7.4:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.