VulnerabilityModified
CVE-2018-8042
Apache Ambari, version 2.5.0 to 2.6.2, passwords for Hadoop credential stores are exposed in Ambari Agent informational log messages when the credential store feature is enabled for eligible services.
HIGH 8.1EPSS 1.75%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.75%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Apache Ambari, version 2.5.0 to 2.6.2, passwords for Hadoop credential stores are exposed in Ambari Agent informational log messages when the credential store feature is enabled for eligible services. For example, Hive and Oozie.
- CVSS 3.0
- 8.1 HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.75% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-209
- Affected
- apache/ambari
- Source
- security@apache.org
References
- http://www.securityfocus.com/bid/104869Broken Link
- https://cwiki.apache.org/confluence/display/AMBARI/Ambari+Vulnerabilities#AmbariVulnerabilities-CVE-2018-8042Vendor Advisory
- http://www.securityfocus.com/bid/104869Broken Link
- https://cwiki.apache.org/confluence/display/AMBARI/Ambari+Vulnerabilities#AmbariVulnerabilities-CVE-2018-8042Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.