CVE-2020-13946

Description

In Apache Cassandra, all versions prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2, it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry to perform a man-in-the-middle attack and capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and perform unauthorised operations. Users should also be aware of CVE-2019-2684, a JRE vulnerability that enables this issue to be exploited remotely.

Risk Information

Base Score
5.9
MODERATE
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
0.472

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2020-13946 are fixed in Apache-cassandra-all 2.1.12Windows
Vulnerabilities CVE-2020-13946 are fixed in Apache-cassandra-all 2.2.18Windows
Vulnerabilities CVE-2020-13946 are fixed in Apache-cassandra-all 3.0.22Windows
Vulnerabilities CVE-2020-13946 are fixed in Apache-cassandra-all 3.11.8Windows
Vulnerabilities CVE-2020-13946 are fixed in Apache-cassandra-all 4.0Windows
Multiple Vulnerabilities are affected in Netapp Oncommand Insight -Windows
Vulnerabilities CVE-2020-13946 are fixed in Apache-cassandra-all for Linux 2.1.12Linux
Vulnerabilities CVE-2020-13946 are fixed in Apache-cassandra-all for Linux 2.2.18Linux
Vulnerabilities CVE-2020-13946 are fixed in Apache-cassandra-all for Linux 3.0.22Linux
Vulnerabilities CVE-2020-13946 are fixed in Apache-cassandra-all for Linux 3.11.8Linux
Vulnerabilities CVE-2020-13946 are fixed in Apache-cassandra-all for Linux 4.0Linux
Exposure of Resource to Wrong Sphere Vulnerability (CVE-2020-13946)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234