CVE-2020-13946
Summary
| CVE | CVE-2020-13946 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-09-01 21:15:00 UTC |
| Updated | 2023-11-07 03:17:00 UTC |
| Description | In Apache Cassandra, all versions prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2, it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry to perform a man-in-the-middle attack and capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and perform unauthorised operations. Users should also be aware of CVE-2019-2684, a JRE vulnerability that enables this issue to be exploited remotely. |
Risk And Classification
Problem Types: CWE-668
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Cassandra | All | All | All | All |
| Application | Apache | Cassandra | 4.0.0 | alpha1 | All | All |
| Application | Apache | Cassandra | 4.0.0 | alpha2 | All | All |
| Application | Apache | Cassandra | 4.0.0 | alpha3 | All | All |
| Application | Apache | Cassandra | 4.0.0 | alpha4 | All | All |
| Application | Apache | Cassandra | 4.0.0 | beta1 | All | All |
| Application | Apache | Cassandra | All | All | All | All |
| Application | Apache | Cassandra | 4.0.0 | alpha1 | All | All |
| Application | Apache | Cassandra | 4.0.0 | alpha2 | All | All |
| Application | Apache | Cassandra | 4.0.0 | alpha3 | All | All |
| Application | Apache | Cassandra | 4.0.0 | alpha4 | All | All |
| Application | Apache | Cassandra | 4.0.0 | beta1 | All | All |
| Application | Netapp | Oncommand Insight | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Pony Mail! | MLIST | lists.apache.org | Mailing List, Vendor Advisory |
| Pony Mail! | lists.apache.org | ||
| Pony Mail! | MLIST | lists.apache.org | |
| CVE-2020-13946 Apache Cassandra Vulnerability in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| Pony Mail! | lists.apache.org | ||
| Pony Mail! | lists.apache.org | ||
| Pony Mail! | MLIST | lists.apache.org | Mailing List, Vendor Advisory |
| Pony Mail! | MISC | lists.apache.org | Mailing List, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 982396 Java (maven) Security Update for org.apache.cassandra:cassandra-all (GHSA-24ww-mc5x-xc43)