CVE-2015-0225: Command Injection
The default configuration in Apache Cassandra 1.2.0 through 1.2.19, 2.0.0 through 2.0.13, and 2.1.0 through 2.1.3 binds an unauthenticated JMX/RMI interface to all network interfaces, which allows remote attackers to execute arbitrary Java code via an RMI request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0225?
CVE-2015-0225 is considered critical due to its potential for remote code execution.
How do I fix CVE-2015-0225?
To fix CVE-2015-0225, update Apache Cassandra to a version that is not affected, such as 2.1.4 or later.
What versions of Apache Cassandra are affected by CVE-2015-0225?
CVE-2015-0225 affects Apache Cassandra versions 1.2.0 through 1.2.19, 2.0.0 through 2.0.13, and 2.1.0 through 2.1.3.
Can CVE-2015-0225 be exploited remotely?
Yes, CVE-2015-0225 can be exploited by remote attackers to execute arbitrary Java code.
What component of Apache Cassandra is vulnerable in CVE-2015-0225?
The vulnerability in CVE-2015-0225 lies in the unauthenticated JMX/RMI interface that binds to all network interfaces.