RMI Rebind Vulnerability in Apache Cassandra Affects User Credential Security
CVE-2020-13946
What is CVE-2020-13946?
In Apache Cassandra, various versions prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8, and 4.0-beta2, a local attacker can exploit the RMI registry to conduct a man-in-the-middle attack. This vulnerability allows the attacker to capture user credentials—including usernames and passwords—used for accessing the JMX interface. Once the attacker has these credentials, they can perform unauthorized operations within the system. It is also critical to note that the JRE vulnerability identified in CVE-2019-2684 can facilitate this exploit remotely.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Apache Cassandra All versions prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved