Vulnerability Description
In Apache Cassandra, all versions prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2, it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry to perform a man-in-the-middle attack and capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and perform unauthorised operations. Users should also be aware of CVE-2019-2684, a JRE vulnerability that enables this issue to be exploited remotely.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Cassandra | < 2.1.22 |
| Netapp | Oncommand Insight | - |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread.html/r1fd117082b992e7d43c1286e966c285f98aa362e68
- https://lists.apache.org/thread.html/r718e01f61b35409a4f7a3ccbc1cb5136a1558a9f9c
- https://lists.apache.org/thread.html/rab8d90d28f944d84e4d7852f355a25c89451ae02c2
- https://lists.apache.org/thread.html/rcd7544b24d8fc32b7950ec4c117052410b661babaaMailing ListVendor Advisory
- https://security.netapp.com/advisory/ntap-20210521-0005/Third Party Advisory
- https://lists.apache.org/thread.html/r1fd117082b992e7d43c1286e966c285f98aa362e68
- https://lists.apache.org/thread.html/r718e01f61b35409a4f7a3ccbc1cb5136a1558a9f9c
- https://lists.apache.org/thread.html/rab8d90d28f944d84e4d7852f355a25c89451ae02c2
- https://lists.apache.org/thread.html/rcd7544b24d8fc32b7950ec4c117052410b661babaaMailing ListVendor Advisory
- https://security.netapp.com/advisory/ntap-20210521-0005/Third Party Advisory
FAQ
What is CVE-2020-13946?
CVE-2020-13946 is a vulnerability with a CVSS score of 5.9 (MEDIUM). In Apache Cassandra, all versions prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2, it is possible for a local attacker without access to the Apache Cassandra process or configuration files to ma...
How severe is CVE-2020-13946?
CVE-2020-13946 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-13946?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Cassandra, Netapp Oncommand Insight.