Remote Code Execution Vulnerability in Apache Cassandra by The Apache Software Foundation
CVE-2018-8016
9.8CRITICAL
What is CVE-2018-8016?
The default configuration of Apache Cassandra versions 3.8 through 3.11.1 exposes an unauthenticated JMX/RMI interface across all network interfaces. This configuration flaw enables remote attackers to send crafted RMI requests, potentially allowing execution of arbitrary Java code on the target system. This vulnerability is a regression of a previous issue and has been addressed in the later 3.11.2 release, which is crucial for securing instances of Apache Cassandra against unauthorized remote access.
Affected Version(s)
Apache Cassandra Apache Cassandra 3.8 to 3.11.1