REDHAT-BUG-1875830: Medium severity apache cassandra vulnerability
In Apache Cassandra, all versions prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2, it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry to perform a man-in-the-middle attack and capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and perform unauthorised operations. Users should also be aware of CVE-2019-2684, a JRE vulnerability that enables this issue to be exploited remotely.
Reference: https://lists.apache.org/thread.html/rcd7544b24d8fc32b7950ec4c117052410b661babaa857fb1fc641152%40%3Cuser.cassandra.apache.org%3E
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1875830?
The severity of REDHAT-BUG-1875830 is classified as critical due to the potential for man-in-the-middle attacks.
How do I fix REDHAT-BUG-1875830?
To fix REDHAT-BUG-1875830, upgrade to Apache Cassandra versions 2.1.22, 2.2.18, 3.0.22, 3.11.8 or 4.0-beta2.
Which versions of Apache Cassandra are affected by REDHAT-BUG-1875830?
All versions of Apache Cassandra prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2 are affected by REDHAT-BUG-1875830.
Can a remote attacker exploit REDHAT-BUG-1875830?
No, REDHAT-BUG-1875830 requires a local attacker to exploit the vulnerability.
What type of attack can REDHAT-BUG-1875830 facilitate?
REDHAT-BUG-1875830 can facilitate a man-in-the-middle attack that can capture user names and passwords.