CVE-2020-17516
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Apache Cassandra versions 2.1.0 to 2.1.22, 2.2.0 to 2.2.19, 3.0.0 to 3.0.23, and 3.11.0 to 3.11.9, when using 'dc' or 'rack' internode_encryption setting, allows both encrypted and unencrypted internode connections. A misconfigured node or a malicious user can use the unencrypted connection despite not being in the same rack or dc, and bypass mutual TLS requirement.
Apache Cassandra versiones 2.1.0 hasta 2.1.22, versiones 2.2.0 hasta 2.2.19, versiones 3.0.0 hasta 3.0.23 y versiones 3.11.0 hasta 3.11.9, cuando se usa la configuración internode_encryption de "dc" o "rack", permite ambas conexiones de entre nodo cifradas y no cifradas. Un nodo configurado inapropiadamente o un usuario malicioso pueden usar la conexión no cifrada a pesar de no estar en el mismo rack o dc y omitir el requisito mutuo de TLS
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-08-12 CVE Reserved
- 2021-02-03 CVE Published
- 2023-11-08 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-290: Authentication Bypass by Spoofing
CAPEC
References (5)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Search vendor "Apache" | Cassandra Search vendor "Apache" for product "Cassandra" | >= 2.1.0 <= 2.1.22 Search vendor "Apache" for product "Cassandra" and version " >= 2.1.0 <= 2.1.22" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Cassandra Search vendor "Apache" for product "Cassandra" | >= 2.2.0 <= 2.2.19 Search vendor "Apache" for product "Cassandra" and version " >= 2.2.0 <= 2.2.19" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Cassandra Search vendor "Apache" for product "Cassandra" | >= 3.0.0 <= 3.0.23 Search vendor "Apache" for product "Cassandra" and version " >= 3.0.0 <= 3.0.23" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Cassandra Search vendor "Apache" for product "Cassandra" | >= 3.11.0 <= 3.11.9 Search vendor "Apache" for product "Cassandra" and version " >= 3.11.0 <= 3.11.9" | - |
Affected
|