Remote Code Execution Vulnerability in Apache Cassandra by The Apache Software Foundation
CVE-2018-8016

9.8CRITICAL

Key Information:

Vendor
Apache
Vendor
CVE Published:
28 June 2018

Summary

The default configuration of Apache Cassandra versions 3.8 through 3.11.1 exposes an unauthenticated JMX/RMI interface across all network interfaces. This configuration flaw enables remote attackers to send crafted RMI requests, potentially allowing execution of arbitrary Java code on the target system. This vulnerability is a regression of a previous issue and has been addressed in the later 3.11.2 release, which is crucial for securing instances of Apache Cassandra against unauthorized remote access.

Affected Version(s)

Apache Cassandra Apache Cassandra 3.8 to 3.11.1

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.