漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
The default configuration in Apache Cassandra 3.8 through 3.11.1 binds an unauthenticated JMX/RMI interface to all network interfaces, which allows remote attackers to execute arbitrary Java code via an RMI request. This issue is a regression of CVE-2015-0225. The regression was introduced in https://issues.apache.org/jira/browse/CASSANDRA-12109. The fix for the regression is implemented in https://issues.apache.org/jira/browse/CASSANDRA-14173. This fix is contained in the 3.11.2 release of Apache Cassandra.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apache Cassandra 安全漏洞
Vulnerability Description
Apache Cassandra是美国阿帕奇(Apache)软件基金会的一套开源分布式NoSQL数据库系统。 Apache Cassandra 3.8版本至3.11.1版本中的默认配置存在安全漏洞,该漏洞源于程序将未认证的JMX/RMI接口捆绑到全部的网络接口上。远程攻击者可通过发送RMI请求利用该漏洞执行任意的Java代码。
CVSS Information
N/A
Vulnerability Type
N/A