Authentication Bypass by Spoofing
CVE-2020-17516
Summary
Apache Cassandra versions before 3.0.24, 3.1.0 to 3.11.9, and 4.x through 4.0-beta3 when using 'dc' or 'rack' internode_encryption setting, allows both encrypted and unencrypted internode connections. A misconfigured node or a malicious user can use the unencrypted connection despite not being in the same rack or dc, and bypass mutual TLS requirement.
- LOW
- NETWORK
- NONE
- UNCHANGED
- NONE
- NONE
- HIGH
- NONE
CWE-290 - Authentication Bypass by Spoofing
This attack-focused weakness is caused by improperly implemented authentication schemes that are subject to spoofing attacks.
Advisory Timeline
- Published