CVE-2024-27137
Severity CVSS v4.0:
Pending analysis
Type:
CWE-287
Authentication Issues
Publication date:
04/02/2025
Last modified:
14/07/2025
Description
In Apache Cassandra it is possible for a local attacker without access<br />
to the Apache Cassandra process or configuration files to manipulate <br />
the RMI registry to perform a man-in-the-middle attack and capture user <br />
names and passwords used to access the JMX interface. The attacker can <br />
then use these credentials to access the JMX interface and perform <br />
unauthorized operations.<br />
<br />
<br />
This is same vulnerability that CVE-2020-13946 was issued for, but the Java option was changed in JDK10.<br />
<br />
<br />
This issue affects Apache Cassandra from 4.0.2 through 5.0.2 running Java 11.<br />
<br />
<br />
Operators are recommended to upgrade to a release equal to or later than 4.0.15, 4.1.8, or 5.0.3 which fixes the issue.
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:apache:cassandra:*:*:*:*:*:*:*:* | 4.0.2 (including) | 4.0.15 (excluding) |
| cpe:2.3:a:apache:cassandra:*:*:*:*:*:*:*:* | 4.1.0 (including) | 4.1.8 (excluding) |
| cpe:2.3:a:apache:cassandra:*:*:*:*:*:*:*:* | 5.0.0 (excluding) | 5.0.3 (excluding) |
| cpe:2.3:a:apache:cassandra:5.0.0:-:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:cassandra:5.0.0:beta1:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:cassandra:5.0.0:rc1:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:cassandra:5.0.0:rc2:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



