Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-24ww-mc5x-xc43

Опубликовано: 07 мая 2021
Источник: github
Github: Прошло ревью
CVSS3: 5.9

Описание

Man-in-the-middle attack in Apache Cassandra

In Apache Cassandra, all versions prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2, it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry to perform a man-in-the-middle attack and capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and perform unauthorised operations. Users should also be aware of CVE-2019-2684, a JRE vulnerability that enables this issue to be exploited remotely.

Пакеты

Наименование

org.apache.cassandra:cassandra-all

maven
Затронутые версииВерсия исправления

>= 2.1.0, < 2.1.12

2.1.12

Наименование

org.apache.cassandra:cassandra-all

maven
Затронутые версииВерсия исправления

>= 2.2.0, < 2.2.18

2.2.18

Наименование

org.apache.cassandra:cassandra-all

maven
Затронутые версииВерсия исправления

>= 3.0.0, < 3.0.22

3.0.22

Наименование

org.apache.cassandra:cassandra-all

maven
Затронутые версииВерсия исправления

>= 3.11.0, < 3.11.8

3.11.8

Наименование

org.apache.cassandra:cassandra-all

maven
Затронутые версииВерсия исправления

= 4.0-beta1

4.0-beta2

EPSS

Процентиль: 46%
0.00229
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-668

Связанные уязвимости

CVSS3: 5.9
redhat
больше 5 лет назад

In Apache Cassandra, all versions prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2, it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry to perform a man-in-the-middle attack and capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and perform unauthorised operations. Users should also be aware of CVE-2019-2684, a JRE vulnerability that enables this issue to be exploited remotely.

CVSS3: 5.9
nvd
больше 5 лет назад

In Apache Cassandra, all versions prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2, it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry to perform a man-in-the-middle attack and capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and perform unauthorised operations. Users should also be aware of CVE-2019-2684, a JRE vulnerability that enables this issue to be exploited remotely.

CVSS3: 5.9
debian
больше 5 лет назад

In Apache Cassandra, all versions prior to 2.1.22, 2.2.18, 3.0.22, 3.1 ...

EPSS

Процентиль: 46%
0.00229
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-668