DirectorySecurity Advisories
Sign In
Security Advisories

CGA-c2qf-hfph-rrp7

Published

Last updated

https://images.chainguard.dev/security/CGA-c2qf-hfph-rrp7
Package

cassandra-4.1

Latest Update
Not affected
Aliases
  • CVE-2020-13946
  • GHSA-24ww-mc5x-xc43

Severity

5.9

Medium

CVSS V3

Summary

Man-in-the-middle attack in Apache Cassandra

Description

In Apache Cassandra, all versions prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2, it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry to perform a man-in-the-middle attack and capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and perform unauthorised operations. Users should also be aware of CVE-2019-2684, a JRE vulnerability that enables this issue to be exploited remotely.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images