peter bassill · operator
$ cve CVE-2016-3086 JSON

CVE-2016-3086

9.8
CRITICAL · CVSS 3.0 · EPSS 3.7% (pctl 89)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

The YARN NodeManager in Apache Hadoop 2.6.x before 2.6.5 and 2.7.x before 2.7.3 can leak the password for credential store provider used by the NodeManager to YARN Applications.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.65% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-200
On CISA KEVno
Public exploitnone known
Published2017-09-05
Last modified2026-06-17

Affected (1)

VendorProduct
apachehadoop

References

→ the Explorer  ·  watch your stack  ·  NVD