org.apache.cassandra:cassandra-all@1.2.2 vulnerabilities

  • latest version

    5.0.4

  • latest non vulnerable version

  • first published

    14 years ago

  • latest version published

    2 months ago

  • licenses detected

  • package registry

  • Direct Vulnerabilities

    Known vulnerabilities in the org.apache.cassandra:cassandra-all package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Arbitrary Command Injection

    org.apache.cassandra:cassandra-all is a free and open-source distributed wide column store NoSQL database management system designed to handle large amounts of data across many commodity servers.

    Affected versions of this package are vulnerable to Arbitrary Code Execution. The default configuration in Apache Cassandra 1.2.0 through 1.2.19, 2.0.0 through 2.0.13, and 2.1.0 through 2.1.3 binds an unauthenticated JMX/RMI interface to all network interfaces, which allows remote attackers to execute arbitrary Java code via an RMI request.

    [1.2.0,1.2.19][2.0.0,2.0.13][2.1.0,2.1.3]