CVE-2016-3086: Apache Hadoop
Critical severity, CVSS 9.8. EPSS: 3.7% chance of exploitation in the next 30 days.
The YARN NodeManager in Apache Hadoop 2.6.x before 2.6.5 and 2.7.x before 2.7.3 can leak the password for credential store provider used by the NodeManager to YARN Applications.
Affected products
- Apache Hadoop: version 2.6.0 only; version 2.6.1 only; version 2.6.2 only; version 2.6.3 only; version 2.6.4 only; version 2.7.0 only; …
Published 2017-09-05. Last modified 2026-06-17.