Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-52gq-7j6c-xw6x

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Missing Authentication for Critical Function in Apache Cassandra

The default configuration in Apache Cassandra 3.8 through 3.11.1 binds an unauthenticated JMX/RMI interface to all network interfaces, which allows remote attackers to execute arbitrary Java code via an RMI request. This issue is a regression of CVE-2015-0225. The regression was introduced in https://issues.apache.org/jira/browse/CASSANDRA-12109. The fix for the regression is implemented in https://issues.apache.org/jira/browse/CASSANDRA-14173. This fix is contained in the 3.11.2 release of Apache Cassandra.

Пакеты

Наименование

org.apache.cassandra:cassandra-all

maven
Затронутые версииВерсия исправления

>= 3.8, <= 3.11.1

3.11.2

EPSS

Процентиль: 69%
0.00609
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 8.1
redhat
больше 7 лет назад

The default configuration in Apache Cassandra 3.8 through 3.11.1 binds an unauthenticated JMX/RMI interface to all network interfaces, which allows remote attackers to execute arbitrary Java code via an RMI request. This issue is a regression of CVE-2015-0225. The regression was introduced in https://issues.apache.org/jira/browse/CASSANDRA-12109. The fix for the regression is implemented in https://issues.apache.org/jira/browse/CASSANDRA-14173. This fix is contained in the 3.11.2 release of Apache Cassandra.

CVSS3: 9.8
nvd
больше 7 лет назад

The default configuration in Apache Cassandra 3.8 through 3.11.1 binds an unauthenticated JMX/RMI interface to all network interfaces, which allows remote attackers to execute arbitrary Java code via an RMI request. This issue is a regression of CVE-2015-0225. The regression was introduced in https://issues.apache.org/jira/browse/CASSANDRA-12109. The fix for the regression is implemented in https://issues.apache.org/jira/browse/CASSANDRA-14173. This fix is contained in the 3.11.2 release of Apache Cassandra.

CVSS3: 9.8
debian
больше 7 лет назад

The default configuration in Apache Cassandra 3.8 through 3.11.1 binds ...

EPSS

Процентиль: 69%
0.00609
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-306