Apache / Cassandra
16 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-32588 | Apache Cassandra: Authenticated DoS via ALTER ROLE Password Hashing | LOW | 2.3 | Apr 7, 2026 |
| CVE-2026-27315 | Apache Cassandra: cqlsh history sensitive information leak | MEDIUM | 6.9 | Apr 7, 2026 |
| CVE-2026-27314 | Apache Cassandra: Privilege escalation via ADD IDENTITY authorization bypass | HIGH | 8.8 | Apr 7, 2026 |
| CVE-2025-26467 | Apache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actions (4.0.16 only) | HIGH | 8.8 | Aug 25, 2025 |
| CVE-2024-27137 | Apache Cassandra: unrestricted deserialization of JMX authentication credentials | MEDIUM | 5.9 | Feb 4, 2025 |
| CVE-2025-24860 | Apache Cassandra: CassandraNetworkAuthorizer and CassandraCIDRAuthorizer can be bypassed allowing access to different network regions | MEDIUM | 5.4 | Feb 4, 2025 |
| CVE-2025-23015 | Apache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actions | HIGH | 8.8 | Feb 4, 2025 |
| CVE-2023-30601 | Apache Cassandra: Privilege escalation when enabling FQL/Audit logs | HIGH | 7.8 | May 30, 2023 |
| CVE-2021-44521 | Remote code execution for scripted UDFs | CRITICAL | 9.1 | Feb 11, 2022 |
| CVE-2020-17516 | cassandra: internode encryption enforcement vulnerability | HIGH | 7.5 | Feb 3, 2021 |
| CVE-2020-13946 | cassandra: allows manipulation of the RMI registry to perform a MITM attack and capture user names and passwords used to access the JMX interface | MEDIUM | 5.9 | Sep 1, 2020 |
| CVE-2019-2684 | OpenJDK: Incorrect skeleton selection in RMI registry server-side dispatch handling (RMI, 8218453) | MEDIUM | 5.9 | Apr 23, 2019 |
| CVE-2018-8016 | cassandra: Unauthenticated JMX/RMI interface bound to all network interfaces (Regression of CVE-2015-0225) | CRITICAL | 9.8 | Jun 28, 2018 |
| CVE-2016-4970 | netty: Infinite loop vulnerability when handling renegotiation using SslProvider.OpenSsl | HIGH | 7.5 | Apr 13, 2017 |
| CVE-2016-3427 KEV | OpenJDK: unrestricted deserialization of authentication credentials (JMX, 8144430) | CRITICAL | 9.8 | Apr 21, 2016 |
| CVE-2015-0225 | Cassandra: remote code execution via unauthenticated JMX/RMI interface | HIGH | 7.5 | Apr 3, 2015 |
Showing 1 to 16 of 16 CVEs