Re: CVE-2020-13946 Apache Cassandra RMI Rebind Vulnerability

2020-09-11 Thread Jeremiah D Jordan
rsion. >> >> Regards >> Manish >> >> On Tue, Sep 1, 2020 at 8:03 PM Sam Tunnicliffe > <mailto:s...@beobal.com>> wrote: >> CVE-2020-13946 Apache Cassandra RMI Rebind Vulnerability >> >> Versions Affected: >> All versions prior to: 2.1.22

Re: CVE-2020-13946 Apache Cassandra RMI Rebind Vulnerability

2020-09-02 Thread Sam Tunnicliffe
; Regards > Manish > > On Tue, Sep 1, 2020 at 8:03 PM Sam Tunnicliffe <mailto:s...@beobal.com>> wrote: > CVE-2020-13946 Apache Cassandra RMI Rebind Vulnerability > > Versions Affected: > All versions prior to: 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2 > >

Re: CVE-2020-13946 Apache Cassandra RMI Rebind Vulnerability

2020-09-01 Thread manish khandelwal
Hi Sam Is there any alternative to avoid this vulnerability? Like upgrade to specific JVM version. Regards Manish On Tue, Sep 1, 2020 at 8:03 PM Sam Tunnicliffe wrote: > CVE-2020-13946 Apache Cassandra RMI Rebind Vulnerability > > Versions Affected: > All versions prior to: 2.

CVE-2020-13946 Apache Cassandra RMI Rebind Vulnerability

2020-09-01 Thread Sam Tunnicliffe
CVE-2020-13946 Apache Cassandra RMI Rebind Vulnerability Versions Affected: All versions prior to: 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2 Description: It is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry