Apache Cassandra Remote Code Execution Vulnerability
Release date:
Updated on:
Affected Systems:
Apache Group Cassandra 2.1.0-2.1.3
Apache Group Cassandra 2.0.0-2.0.13
Apache Group Cassandra 1.2.0-1.2.19
Description:
CVE (CAN) ID: CVE-2015-0225
Apache Cassandra is an open-source distributed database management system developed by Facebook to store extremely large data.
In the default configuration of Cassandra, all network interfaces are bound with unauthenticated JMX/RMI interfaces. Since RMI is an API for transmitting and remotely serializing Java, you only need to access this interface, attackers can execute arbitrary code with the current user permission.
<* Source: Georgi gesev
Link: http://secunia.com/advisories/63739/
Https://wiki.apache.org/cassandra/JmxSecurity
*>
Suggestion:
Vendor patch:
Apache Group
------------
Apache Group has released a Security Bulletin (CVE-2015-0225) and patches for this:
The CVE-2015-0225: Apache Cassandra remote execution of arbitrary code
Link: https://wiki.apache.org/cassandra/JmxSecurity
This article permanently updates the link address: