Man-in-the-Middle (MitM) Affecting org.apache.cassandra:cassandra-all package, versions [2.1.0,2.3.0)[3.0.0,3.0.24)[3.11.0,3.11.10)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.22% (61st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGAPACHECASSANDRA-1069886
  • published3 Feb 2021
  • disclosed2 Feb 2021
  • creditJon Meredith

Introduced: 2 Feb 2021

CVE-2020-17516  (opens in a new tab)
CWE-300  (opens in a new tab)

How to fix?

Upgrade org.apache.cassandra:cassandra-all to version 2.3.0, 3.0.24, 3.11.10 or higher.

Overview

org.apache.cassandra:cassandra-all is a maven plugin for the Apache Cassandra Project. Which, develops a highly scalable second-generation distributed database, bringing together Dynamo's fully distributed design and Bigtable's ColumnFamily-based data model.

Affected versions of this package are vulnerable to Man-in-the-Middle (MitM). When using dc or rack internode_encryption setting, a Cassandra instance allows both encrypted and unencrypted connections. A misconfigured node or a malicious user can use the unencrypted connection despite not being in the same rack or dc, and bypass mutual TLS requirement.

CVSS Scores

version 3.1