CVE-2015-1776: Apache Hadoop
Medium severity, CVSS 6.2. EPSS: 0.3% chance of exploitation in the next 30 days.
Apache Hadoop 2.6.x encrypts intermediate data generated by a MapReduce job and stores it along with the encryption key in a credentials file on disk when the Intermediate data encryption feature is enabled, which allows local users to obtain sensitive information by reading the file.
Affected products
- Apache Hadoop: version 2.6.0 only; version 2.6.1 only; version 2.6.2 only; version 2.6.3 only; version 2.6.4 only
Published 2016-04-19. Last modified 2026-06-17.