Skip to main content

Authentication Bypass by Spoofing

CVE-2020-17516

Severity High
Score 7.5/10

Summary

Apache Cassandra versions before 3.0.24, 3.1.0 to 3.11.9, and 4.x through 4.0-beta3 when using 'dc' or 'rack' internode_encryption setting, allows both encrypted and unencrypted internode connections. A misconfigured node or a malicious user can use the unencrypted connection despite not being in the same rack or dc, and bypass mutual TLS requirement.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • HIGH
  • NONE

CWE-290 - Authentication Bypass by Spoofing

This attack-focused weakness is caused by improperly implemented authentication schemes that are subject to spoofing attacks.

Advisory Timeline

  • Published