Description
Apache Hadoop is a collection of open-source software utilities that facilitate using a network of many computers to solve problems involving massive amounts of data and computation.
Yarn ResourceManager (RM) is the master that arbitrates all the available cluster resources and thus helps manage the distributed applications running on the YARN system.
By default, the Hadoop YARN ResourceManager allows any request to be made by anyone. This service should not be accessible on a production website without authentication.
Remediation
Disable external access to the Hadoop YARN ResourceManager.
References
Related Vulnerabilities
Oracle PeopleSoft SSO weak secret key
Unrestricted access to Odoo DB manager
MyBB Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-3759)
nginx range filter integer overflow
TYPO3 Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-1607)