In Apache Cassandra it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry to perform a man-in-the-middle attack and capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and perform unauthorized operations. This is same vulnerability that CVE-2020-13946 was issued for, but the Java option was changed in JDK10. This issue affects Apache Cassandra from 4.0.2 through 5.0.2 running Java 11. Operators are recommended to upgrade to a release equal to or later than 4.0.15, 4.1.8, or 5.0.3 which fixes the issue.
History

Sat, 15 Feb 2025 01:30:00 +0000

Type Values Removed Values Added
References

Fri, 07 Feb 2025 14:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 06 Feb 2025 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287

Thu, 06 Feb 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Feb 2025 10:30:00 +0000

Type Values Removed Values Added
Description In Apache Cassandra it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry to perform a man-in-the-middle attack and capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and perform unauthorized operations. This is same vulnerability that CVE-2020-13946 was issued for, but the Java option was changed in JDK10. This issue affects Apache Cassandra from 4.0.2 through 5.0.2 running Java 11. Operators are recommended to upgrade to a release equal to or later than 4.0.15, 4.1.8, or 5.0.3 which fixes the issue.
Title Apache Cassandra: unrestricted deserialization of JMX authentication credentials
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2025-02-15T00:10:33.257Z

Reserved: 2024-02-20T12:29:07.597Z

Link: CVE-2024-27137

cve-icon Vulnrichment

Updated: 2025-02-15T00:10:33.257Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-02-04T11:15:08.220

Modified: 2025-02-15T01:15:10.420

Link: CVE-2024-27137

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-02-04T10:19:44Z

Links: CVE-2024-27137 - Bugzilla