Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-8016

Опубликовано: 26 июн. 2018
Источник: redhat
CVSS3: 8.1

Описание

The default configuration in Apache Cassandra 3.8 through 3.11.1 binds an unauthenticated JMX/RMI interface to all network interfaces, which allows remote attackers to execute arbitrary Java code via an RMI request. This issue is a regression of CVE-2015-0225. The regression was introduced in https://issues.apache.org/jira/browse/CASSANDRA-12109. The fix for the regression is implemented in https://issues.apache.org/jira/browse/CASSANDRA-14173. This fix is contained in the 3.11.2 release of Apache Cassandra.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Operations Network 3cassandraNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-306
https://bugzilla.redhat.com/show_bug.cgi?id=1595650cassandra: Unauthenticated JMX/RMI interface bound to all network interfaces (Regression of CVE-2015-0225)

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
больше 7 лет назад

The default configuration in Apache Cassandra 3.8 through 3.11.1 binds an unauthenticated JMX/RMI interface to all network interfaces, which allows remote attackers to execute arbitrary Java code via an RMI request. This issue is a regression of CVE-2015-0225. The regression was introduced in https://issues.apache.org/jira/browse/CASSANDRA-12109. The fix for the regression is implemented in https://issues.apache.org/jira/browse/CASSANDRA-14173. This fix is contained in the 3.11.2 release of Apache Cassandra.

CVSS3: 9.8
debian
больше 7 лет назад

The default configuration in Apache Cassandra 3.8 through 3.11.1 binds ...

CVSS3: 9.8
github
больше 3 лет назад

Missing Authentication for Critical Function in Apache Cassandra

8.1 High

CVSS3