📦 Cassandra

by Apache

🔍 What is Cassandra?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-44521

CRITICAL CVSS 9.1 Feb 11, 2022

This vulnerability allows authenticated attackers with permissions to create user-defined functions in Apache Cassandra to execute arbitrary code on the host when specific unsafe configurations are en...

CVE-2025-26467

HIGH CVSS 8.8 Aug 25, 2025

This CVE describes a privilege escalation vulnerability in Apache Cassandra where a user with MODIFY permission on all keyspaces can gain superuser privileges by performing unsafe actions on system re...

CVE-2025-23015

HIGH CVSS 8.8 Feb 4, 2025

This vulnerability allows users with MODIFY permission on all keyspaces in Apache Cassandra to escalate privileges to superuser by performing unsafe actions on system resources. It affects all Apache ...

CVE-2023-30601

HIGH CVSS 7.8 May 30, 2023

This vulnerability allows users with JMX access to escalate privileges and execute arbitrary commands as the Apache Cassandra service account when enabling FQL/Audit logs. It affects Apache Cassandra ...

CVE-2020-17516

HIGH CVSS 7.5 Feb 3, 2021

This vulnerability in Apache Cassandra allows unencrypted internode connections even when TLS is configured, enabling attackers to bypass mutual TLS requirements. It affects Cassandra clusters using '...

CVE-2024-27137

MEDIUM CVSS 5.3 Feb 4, 2025

This vulnerability allows a local attacker to perform a man-in-the-middle attack on Apache Cassandra's RMI registry, capturing JMX interface credentials. Attackers can then use these credentials to pe...