CVE-2021-44521: fallo en Apache Cassandra
Remote code execution for scripted UDFs
Publicada el · Actualizada el
30Vexday Risk Score
Corrige pronto. Ella tiene exploit funcional público.
ssvc Attendepss 58%
probabilidad de explotación
58%top 1% de las CVE
explotación observada
noninguna fuente lo reporta
When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enable_user_defined_functions_threads: false it is possible for an attacker to execute arbitrary code on the host. The attacker would need to have enough permissions to create user defined functions in the cluster to be able to exploit this. Note that this configuration is documented as unsafe, and will continue to be considered unsafe after this CVE.
Productos afectados
Apache Software Foundation · Apache CassandraCVEs relacionadas — Apache Cassandra
En el mismo producto, de las más peligrosas a las menos.
CVE-2018-8016—CVE-2018-8016EPSS 2.3%CVE-2025-24860MEDIUMApache Cassandra: CassandraNetworkAuthorizer and CassandraCIDRAuthorizer can be bypassed allowing access to different network regionsEPSS 1.1%CVE-2025-23015HIGHApache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actionsEPSS 1.0%CVE-2026-32588MEDIUMApache Cassandra: Authenticated DoS via ALTER ROLE Password HashingEPSS 0.7%CVE-2025-26467HIGHApache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actions (4.0.16 only)EPSS 0.5%CVE-2023-30601HIGHApache Cassandra: Privilege escalation when enabling FQL/Audit logsEPSS 0.3%
Referencias
https://jfrog.com/blog/cve-2021-44521-exploiting-apache-cassandra-user-defined-functions-for-remote-code-execution/https://lists.apache.org/thread/y4nb9s4co34j8hdfmrshyl09lokm7356https://security.netapp.com/advisory/ntap-20220225-0001/http://www.openwall.com/lists/oss-security/2022/02/11/4