CVE-2021-44521: falha em Apache Cassandra
Remote code execution for scripted UDFs
Publicada em · Atualizada em
30Vexday Risk Score
Corrija em breve. Ela tem exploit funcional público.
ssvc Attendepss 58%
probabilidade de exploração
58%top 1% das CVEs
exploração observada
nãonenhuma fonte reporta
When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enable_user_defined_functions_threads: false it is possible for an attacker to execute arbitrary code on the host. The attacker would need to have enough permissions to create user defined functions in the cluster to be able to exploit this. Note that this configuration is documented as unsafe, and will continue to be considered unsafe after this CVE.
Produtos afetados
Apache Software Foundation · Apache CassandraCVEs relacionadas — Apache Cassandra
No mesmo produto, das mais perigosas para as menos.
CVE-2018-8016—CVE-2018-8016EPSS 2.3%CVE-2025-24860MEDIUMApache Cassandra: CassandraNetworkAuthorizer and CassandraCIDRAuthorizer can be bypassed allowing access to different network regionsEPSS 1.1%CVE-2025-23015HIGHApache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actionsEPSS 1.0%CVE-2026-32588MEDIUMApache Cassandra: Authenticated DoS via ALTER ROLE Password HashingEPSS 0.7%CVE-2025-26467HIGHApache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actions (4.0.16 only)EPSS 0.5%CVE-2023-30601HIGHApache Cassandra: Privilege escalation when enabling FQL/Audit logsEPSS 0.3%
Referências
https://jfrog.com/blog/cve-2021-44521-exploiting-apache-cassandra-user-defined-functions-for-remote-code-execution/https://lists.apache.org/thread/y4nb9s4co34j8hdfmrshyl09lokm7356https://security.netapp.com/advisory/ntap-20220225-0001/http://www.openwall.com/lists/oss-security/2022/02/11/4