CVE Database
/

CVE-2020-13946

Back to search

CVE-2020-13946

Published: Sep 1, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

In Apache Cassandra, all versions prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2, it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry to perform a man-in-the-middle attack and capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and perform unauthorised operations. Users should also be aware of CVE-2019-2684, a JRE vulnerability that enables this issue to be exploited remotely.

VendorProductVersions

n/a

Apache Cassandra

affected
All versions prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now