REDHAT-BUG-1875830: Medium severity apache cassandra vulnerability

Published Sep 4, 2020
·
Updated

In Apache Cassandra, all versions prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2, it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry to perform a man-in-the-middle attack and capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and perform unauthorised operations. Users should also be aware of CVE-2019-2684, a JRE vulnerability that enables this issue to be exploited remotely.

Reference: https://lists.apache.org/thread.html/rcd7544b24d8fc32b7950ec4c117052410b661babaa857fb1fc641152%40%3Cuser.cassandra.apache.org%3E

Affected Software

1 affected component
Apache Cassandra<2.1.22, <2.2.18, <3.0.22, <3.11.8, <4.0-beta2

Event History

Sep 4, 2020
Data Sourced
via Red Hat·01:38 PM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-1875830?

The severity of REDHAT-BUG-1875830 is classified as critical due to the potential for man-in-the-middle attacks.

2

How do I fix REDHAT-BUG-1875830?

To fix REDHAT-BUG-1875830, upgrade to Apache Cassandra versions 2.1.22, 2.2.18, 3.0.22, 3.11.8 or 4.0-beta2.

3

Which versions of Apache Cassandra are affected by REDHAT-BUG-1875830?

All versions of Apache Cassandra prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2 are affected by REDHAT-BUG-1875830.

4

Can a remote attacker exploit REDHAT-BUG-1875830?

No, REDHAT-BUG-1875830 requires a local attacker to exploit the vulnerability.

5

What type of attack can REDHAT-BUG-1875830 facilitate?

REDHAT-BUG-1875830 can facilitate a man-in-the-middle attack that can capture user names and passwords.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203