CVE-2020-17516

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
03/02/2021
Last modified:
07/11/2023

Description

Apache Cassandra versions 2.1.0 to 2.1.22, 2.2.0 to 2.2.19, 3.0.0 to 3.0.23, and 3.11.0 to 3.11.9, when using 'dc' or 'rack' internode_encryption setting, allows both encrypted and unencrypted internode connections. A misconfigured node or a malicious user can use the unencrypted connection despite not being in the same rack or dc, and bypass mutual TLS requirement.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:cassandra:*:*:*:*:*:*:*:* 2.1.0 (including) 2.1.22 (including)
cpe:2.3:a:apache:cassandra:*:*:*:*:*:*:*:* 2.2.0 (including) 2.2.19 (including)
cpe:2.3:a:apache:cassandra:*:*:*:*:*:*:*:* 3.0.0 (including) 3.0.23 (including)
cpe:2.3:a:apache:cassandra:*:*:*:*:*:*:*:* 3.11.0 (including) 3.11.9 (including)