Remote Code Execution Vulnerability in Apache Cassandra by The Apache Software Foundation
CVE-2018-8016
9.8CRITICAL
Summary
The default configuration of Apache Cassandra versions 3.8 through 3.11.1 exposes an unauthenticated JMX/RMI interface across all network interfaces. This configuration flaw enables remote attackers to send crafted RMI requests, potentially allowing execution of arbitrary Java code on the target system. This vulnerability is a regression of a previous issue and has been addressed in the later 3.11.2 release, which is crucial for securing instances of Apache Cassandra against unauthorized remote access.
Affected Version(s)
Apache Cassandra Apache Cassandra 3.8 to 3.11.1
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved