Internode Encryption Vulnerability in Apache Cassandra by The Apache Software Foundation
CVE-2020-17516
7.5HIGH
Summary
Apache Cassandra allows both encrypted and unencrypted internode connections due to a misconfiguration in its 'dc' or 'rack' internode_encryption setting. This vulnerability occurs when a node is set up incorrectly, enabling a malicious user to bypass mutual TLS requirements and exploit unencrypted connections, even if they are not in the same data center or rack. Administrators must ensure correct configurations to prevent unauthorized access and protect data integrity.
Affected Version(s)
Apache Cassandra 2.1.0 to 2.1.22
Apache Cassandra 2.2.0 to 2.2.19
Apache Cassandra 3.0.0 to 3.0.23
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved