CVE-2021-44521: vulnerability in Apache Cassandra
Remote code execution for scripted UDFs
Published · Updated
30Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 58%
exploitation probability
58%top 1% of all CVEs
observed exploitation
nono source reports it
When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enable_user_defined_functions_threads: false it is possible for an attacker to execute arbitrary code on the host. The attacker would need to have enough permissions to create user defined functions in the cluster to be able to exploit this. Note that this configuration is documented as unsafe, and will continue to be considered unsafe after this CVE.
Affected products
Apache Software Foundation · Apache CassandraRelated CVEs — Apache Cassandra
In the same product, most dangerous first.
CVE-2018-8016—CVE-2018-8016EPSS 2.3%CVE-2025-24860MEDIUMApache Cassandra: CassandraNetworkAuthorizer and CassandraCIDRAuthorizer can be bypassed allowing access to different network regionsEPSS 1.1%CVE-2025-23015HIGHApache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actionsEPSS 1.0%CVE-2026-32588MEDIUMApache Cassandra: Authenticated DoS via ALTER ROLE Password HashingEPSS 0.7%CVE-2025-26467HIGHApache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actions (4.0.16 only)EPSS 0.5%CVE-2023-30601HIGHApache Cassandra: Privilege escalation when enabling FQL/Audit logsEPSS 0.3%
References
https://jfrog.com/blog/cve-2021-44521-exploiting-apache-cassandra-user-defined-functions-for-remote-code-execution/https://lists.apache.org/thread/y4nb9s4co34j8hdfmrshyl09lokm7356https://security.netapp.com/advisory/ntap-20220225-0001/http://www.openwall.com/lists/oss-security/2022/02/11/4