Apache Ambari 2.x before 2.4.0 includes KDC administrator passwords on the kadmin command line, which allows local users to obtain sensitive information via a process listing.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-4976.json"