← Back

CVE-2021-44521

Published: Feb 11, 2022Modified: Jun 17, 2026

JSON object

Loading...
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Exploitability: 2.3 / Impact: 6.0
Source: NVD

Description

When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enable_user_defined_functions_threads: false it is possible for an attacker to execute arbitrary code on the host. The attacker would need to have enough permissions to create user defined functions in the cluster to be able to exploit this. Note that this configuration is documented as unsafe, and will continue to be considered unsafe after this CVE.

Affected (3)

Products: Apache: Cassandra
1 product
Cassandra
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Apache
From 3.0.0 to 3.0.26
From 3.11.0 to 3.11.12
From 4.0.0 to 4.0.2

References (8)

Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Issue TrackingMailing ListVendor Advisory
Source: security@apache.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingMailing ListVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.