CVE-2018-8042

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
18/07/2018
Last modified:
03/10/2019

Description

Apache Ambari, version 2.5.0 to 2.6.2, passwords for Hadoop credential stores are exposed in Ambari Agent informational log messages when the credential store feature is enabled for eligible services. For example, Hive and Oozie.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:ambari:*:*:*:*:*:*:*:* 2.5.0 (including) 2.6.2 (including)