<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Apache Cassandra</title>
  <link>https://cvedaily.com/pages/tags/apache-cassandra.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/apache-cassandra.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Apache Cassandra</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:51 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-33844 – Improper access control in Azure Managed Instance for Apache Cassandra allows an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33844</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33844</guid>
    <pubDate>Thu, 07 May 2026 22:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-33844</strong></p>
  <p>Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33844">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-33109 – Improper access control in Azure Managed Instance for Apache Cassandra allows an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33109</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33109</guid>
    <pubDate>Thu, 07 May 2026 22:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-33109</strong></p>
  <p>Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33109">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-32588 – Authenticated DoS over CQL in Apache Cassandra 4.0, 4.1, 5.0 allows authenticate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32588</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32588</guid>
    <pubDate>Tue, 07 Apr 2026 17:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-32588</strong></p>
  <p>Authenticated DoS over CQL in Apache Cassandra 4.0, 4.1, 5.0 allows authenticated user to raise query latencies via repeated password changes. Users are recommended to upgrade to version 4.0.20, 4.1.11, 5.0.7, which fixes this issue.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32588">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-27315 – Sensitive Information Leak in cqlsh in Apache Cassandra 4.0 allows access to sen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27315</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27315</guid>
    <pubDate>Tue, 07 Apr 2026 17:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-27315</strong></p>
  <p>Sensitive Information Leak in cqlsh in Apache Cassandra 4.0 allows access to sensitive information, like passwords, from previously executed cqlsh command via  ~/.cassandra/cqlsh_history local file access.  Users are recommended to upgrade to version 4.0.20, which fixes this issue.  -- Description: Cassandra's command-line tool, cqlsh, provides a command history feature that allows users to recal…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27315">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27314 – Privilege escalation in Apache Cassandra 5.0 on an mTLS environment using Mutual...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27314</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27314</guid>
    <pubDate>Tue, 07 Apr 2026 17:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27314</strong></p>
  <p>Privilege escalation in Apache Cassandra 5.0 on an mTLS environment using MutualTlsAuthenticator allows a user with only CREATE permission to associate their own certificate identity with an arbitrary role, including a superuser role, and authenticate as that role via ADD IDENTITY.  Users are recommended to upgrade to version 5.0.7+, which fixes this issue.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-267</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27314">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-36939 – Cassandra Web 0.5.0 contains a directory traversal vulnerability that allows una...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36939</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36939</guid>
    <pubDate>Tue, 27 Jan 2026 16:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-36939</strong></p>
  <p>Cassandra Web 0.5.0 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating path traversal parameters. Attackers can exploit the disabled Rack::Protection module to read sensitive system files like /etc/passwd and retrieve Apache Cassandra database credentials.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36939">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-10703 – Improper Control of Generation of Code ('Code Injection') vulnerability in Progr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10703</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10703</guid>
    <pubDate>Wed, 19 Nov 2025 16:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-10703</strong></p>
  <p>Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion.  The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers, DataDirect Hybrid Data Pipeline JDBC driver and the DataDirect OpenAccess JDBC driver l…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10703">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-10702 – Improper Control of Generation of Code ('Code Injection') vulnerability in Progr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10702</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10702</guid>
    <pubDate>Wed, 19 Nov 2025 16:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-10702</strong></p>
  <p>Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion.   The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers, DataDirect Hybrid Data Pipeline JDBC driver and the DataDirect OpenAccess JDBC driver…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10702">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-26467 – Privilege Defined With Unsafe Actions vulnerability in Apache Cassandra. An user...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-26467</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-26467</guid>
    <pubDate>Mon, 25 Aug 2025 14:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-26467</strong></p>
  <p>Privilege Defined With Unsafe Actions vulnerability in Apache Cassandra. An user with MODIFY permission ON ALL KEYSPACES can escalate privileges to superuser within a targeted Cassandra cluster via unsafe actions to a system resource. Operators granting data MODIFY permission on all keyspaces on affected versions should review data access rules for potential breaches.    This issue affects Apache…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-267</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-26467">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-26511 – Systems running the Instaclustr 
fork of Stratio's Cassandra-Lucene-Index plugin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-26511</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-26511</guid>
    <pubDate>Thu, 13 Feb 2025 16:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-26511</strong></p>
  <p>Systems running the Instaclustr  fork of Stratio's Cassandra-Lucene-Index plugin versions 4.0-rc1-1.0.0  through 4.0.16-1.0.0 and 4.1.2-1.0.0 through 4.1.8-1.0.0, installed into  Apache Cassandra version 4.x, are susceptible to a vulnerability which  when successfully exploited could allow authenticated Cassandra users to  remotely bypass RBAC and escalate their privileges.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-26511">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-24860 – Incorrect Authorization vulnerability in Apache Cassandra allowing users to acce...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24860</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24860</guid>
    <pubDate>Tue, 04 Feb 2025 11:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-24860</strong></p>
  <p>Incorrect Authorization vulnerability in Apache Cassandra allowing users to access a datacenter or IP/CIDR groups they should not be able to when using CassandraNetworkAuthorizer or CassandraCIDRAuthorizer.  Users with restricted data center access can update their own permissions via data control language (DCL) statements on affected versions.     This issue affects Apache Cassandra: from 4.0.0…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24860">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-27137 – In Apache Cassandra it is possible for a local attacker without access
 to the A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-27137</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-27137</guid>
    <pubDate>Tue, 04 Feb 2025 11:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-27137</strong></p>
  <p>In Apache Cassandra it is possible for a local attacker without access  to the Apache Cassandra process or configuration files to manipulate  the RMI registry to perform a man-in-the-middle attack and capture user  names and passwords used to access the JMX interface. The attacker can  then use these credentials to access the JMX interface and perform  unauthorized operations.   This is same vuln…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-27137">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-23015 – Privilege Defined With Unsafe Actions vulnerability in Apache Cassandra. An user...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-23015</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-23015</guid>
    <pubDate>Tue, 04 Feb 2025 10:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-23015</strong></p>
  <p>Privilege Defined With Unsafe Actions vulnerability in Apache Cassandra. An user with MODIFY permission ON ALL KEYSPACES can escalate privileges to superuser within a targeted Cassandra cluster via unsafe actions to a system resource. Operators granting data MODIFY permission on all keyspaces on affected versions should review data access rules for potential breaches.  This issue affects Apache C…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-267</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23015">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-38175 – An improper access control vulnerability in the Azure Managed Instance for Apach...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38175</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38175</guid>
    <pubDate>Tue, 20 Aug 2024 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-38175</strong></p>
  <p>An improper access control vulnerability in the Azure Managed Instance for Apache Cassandra allows an authenticated attacker to elevate privileges over a network.</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38175">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-33972 – Scylladb is a NoSQL data store using the seastar framework, compatible with Apac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-33972</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-33972</guid>
    <pubDate>Wed, 27 Sep 2023 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-33972</strong></p>
  <p>Scylladb is a NoSQL data store using the seastar framework, compatible with Apache Cassandra. Authenticated users who are authorized to create tables in a keyspace can escalate their privileges to access a table in the same keyspace, even if they don't have permissions for that table. This issue has not yet been patched. A workaround to address this issue is to disable CREATE privileges on a keys…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-33972">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-30601 – Privilege escalation when enabling FQL/Audit logs allows user with JMX access to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-30601</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-30601</guid>
    <pubDate>Tue, 30 May 2023 08:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-30601</strong></p>
  <p>Privilege escalation when enabling FQL/Audit logs allows user with JMX access to run arbitrary commands as the user running Apache Cassandra This issue affects Apache Cassandra: from 4.0.0 through 4.0.9, from 4.1.0 through 4.1.1.  WORKAROUND The vulnerability requires nodetool/JMX access to be exploitable, disable access for any non-trusted users.  MITIGATION Upgrade to 4.0.10 or 4.1.2 and leave…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-30601">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-29240 – Scylla is a real-time big data database that is API-compatible with Apache Cassa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-29240</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-29240</guid>
    <pubDate>Thu, 15 Sep 2022 22:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-29240</strong></p>
  <p>Scylla is a real-time big data database that is API-compatible with Apache Cassandra and Amazon DynamoDB. When decompressing CQL frame received from user, Scylla assumes that user-provided uncompressed length is correct. If user provides fake length, that is greater than the real one, part of decompression buffer won't be overwritten, and will be left uninitialized. This can be exploited in sever…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-29240">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-44521 – When running Apache Cassandra with the following configuration: enable_user_defi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-44521</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-44521</guid>
    <pubDate>Fri, 11 Feb 2022 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-44521</strong></p>
  <p>When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enable_user_defined_functions_threads: false it is possible for an attacker to execute arbitrary code on the host. The attacker would need to have enough permissions to create user defined functions in the cluster to be able to exploit this. Note that th…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-44521">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-17516 – Apache Cassandra versions 2.1.0 to 2.1.22, 2.2.0 to 2.2.19, 3.0.0 to 3.0.23, and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-17516</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-17516</guid>
    <pubDate>Wed, 03 Feb 2021 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-17516</strong></p>
  <p>Apache Cassandra versions 2.1.0 to 2.1.22, 2.2.0 to 2.2.19, 3.0.0 to 3.0.23, and 3.11.0 to 3.11.9, when using 'dc' or 'rack' internode_encryption setting, allows both encrypted and unencrypted internode connections. A misconfigured node or a malicious user can use the unencrypted connection despite not being in the same rack or dc, and bypass mutual TLS requirement.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-17516">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-13946 – In Apache Cassandra, all versions prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13946</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13946</guid>
    <pubDate>Tue, 01 Sep 2020 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-13946</strong></p>
  <p>In Apache Cassandra, all versions prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2, it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry to perform a man-in-the-middle attack and capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX in…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13946">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-8016 – The default configuration in Apache Cassandra 3.8 through 3.11.1 binds an unauth...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-8016</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-8016</guid>
    <pubDate>Thu, 28 Jun 2018 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-8016</strong></p>
  <p>The default configuration in Apache Cassandra 3.8 through 3.11.1 binds an unauthenticated JMX/RMI interface to all network interfaces, which allows remote attackers to execute arbitrary Java code via an RMI request. This issue is a regression of CVE-2015-0225. The regression was introduced in https://issues.apache.org/jira/browse/CASSANDRA-12109. The fix for the regression is implemented in https…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-8016">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-0225 – The default configuration in Apache Cassandra 1.2.0 through 1.2.19, 2.0.0 throug...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-0225</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-0225</guid>
    <pubDate>Fri, 03 Apr 2015 14:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-0225</strong></p>
  <p>The default configuration in Apache Cassandra 1.2.0 through 1.2.19, 2.0.0 through 2.0.13, and 2.1.0 through 2.1.3 binds an unauthenticated JMX/RMI interface to all network interfaces, which allows remote attackers to execute arbitrary Java code via an RMI request.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-0225">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
