Internode Encryption Vulnerability in Apache Cassandra by The Apache Software Foundation
CVE-2020-17516

7.5HIGH

Key Information:

Vendor
Apache
Vendor
CVE Published:
3 February 2021

Summary

Apache Cassandra allows both encrypted and unencrypted internode connections due to a misconfiguration in its 'dc' or 'rack' internode_encryption setting. This vulnerability occurs when a node is set up incorrectly, enabling a malicious user to bypass mutual TLS requirements and exploit unencrypted connections, even if they are not in the same data center or rack. Administrators must ensure correct configurations to prevent unauthorized access and protect data integrity.

Affected Version(s)

Apache Cassandra 2.1.0 to 2.1.22

Apache Cassandra 2.2.0 to 2.2.19

Apache Cassandra 3.0.0 to 3.0.23

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.