CVE-2024-27137
Last modified
CVE-2024-27137 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. In Apache Cassandra it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry to perform a man-in-the-middle attack and capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and perform unauthorized operations. This is same vulnerability that CVE-2020-13946 was issued for, but the Java option was changed in JDK10. This issue affects Apache Cassandra from 4.0.2 through 5.0.2 running Java 11. Operators are recommended to upgrade to a release equal to or later than 4.0.15, 4.1.8, or 5.0.3 which fixes the issue.. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
In Apache Cassandra it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry to perform a man-in-the-middle attack and capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and perform unauthorized operations. This is same vulnerability that CVE-2020-13946 was issued for, but the Java option was changed in JDK10. This issue affects Apache Cassandra from 4.0.2 through 5.0.2 running Java 11. Operators are recommended to upgrade to a release equal to or later than 4.0.15, 4.1.8, or 5.0.3 which fixes the issue.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Cassandra | >= 4.0.2, < 4.0.15 |
| Apache | Cassandra | >= 4.1.0, < 4.1.8 |
| Apache | Cassandra | > 5.0.0, < 5.0.3 |
| Apache | Cassandra | 5.0.0 |
References
- https://lists.apache.org/thread/jsk87d9yv8r204mgqpz1qxtp5wcrpysmIssue Tracking, Mailing List, Vendor Advisory
- https://security.netapp.com/advisory/ntap-20250214-0004/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-27137?
How severe is CVE-2024-27137?
How do I fix CVE-2024-27137?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-27130A buffer copy without checking size of input vulnerability h…8.8
- CVE-2024-27132Insufficient sanitization in MLflow leads to XSS when runnin…9.6
- CVE-2024-27133Insufficient sanitization in MLflow leads to XSS when runnin…9.6
- CVE-2024-27134Excessive directory permissions in MLflow leads to local pri…7
- CVE-2024-27135Improper input validation in the Pulsar Function Worker allo…9.9
- CVE-2024-27136XSS in Upload page in Apache JSPWiki 2.12.1 and priors allow…6.1
- CVE-2024-27138** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vuln…7.5
- CVE-2024-27139** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vul…7.5
- CVE-2024-2714A vulnerability has been found in Campcodes Complete Online …6.5
- CVE-2024-27140** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of …5.4
- CVE-2024-27141Toshiba printers use XML communication for the API endpoint …5.9
- CVE-2024-27142Toshiba printers use XML communication for the API endpoint …5.9
Are you affected by CVE-2024-27137?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
