{"id":"GHSA-w7f2-gjxf-2gm9","summary":"Improper Neutralization of Special Elements used in a Command  in Apache Cassandra","details":"The default configuration in Apache Cassandra 1.2.0 through 1.2.19, 2.0.0 through 2.0.13, and 2.1.0 through 2.1.3 binds an unauthenticated JMX/RMI interface to all network interfaces, which allows remote attackers to execute arbitrary Java code via an RMI request.","aliases":["CVE-2015-0225"],"modified":"2024-12-05T05:43:23.250314Z","published":"2022-05-14T02:49:56Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2022-07-06T20:40:57Z","nvd_published_at":"2015-04-03T14:59:00Z","cwe_ids":["CWE-77"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2015-0225"},{"type":"WEB","url":"http://packetstormsecurity.com/files/131249/Apache-Cassandra-Remote-Code-Execution.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2015-1947.html"},{"type":"WEB","url":"http://www.mail-archive.com/user@cassandra.apache.org/msg41819.html"}],"affected":[{"package":{"name":"org.apache.cassandra:apache-cassandra","ecosystem":"Maven","purl":"pkg:maven/org.apache.cassandra/apache-cassandra"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.2.0"},{"fixed":"2.0.14"}]}],"versions":["1.2.0","1.2.1","1.2.10","1.2.11","1.2.12","1.2.13","1.2.14","1.2.15","1.2.16","1.2.17","1.2.18","1.2.19","1.2.2","1.2.3","1.2.4","1.2.5","1.2.6","1.2.7","1.2.8","1.2.9","2.0.0","2.0.0-beta1","2.0.0-beta2","2.0.0-rc1","2.0.0-rc2","2.0.1","2.0.10","2.0.11","2.0.12","2.0.13","2.0.2","2.0.3","2.0.4","2.0.5","2.0.6","2.0.7","2.0.8","2.0.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-w7f2-gjxf-2gm9/GHSA-w7f2-gjxf-2gm9.json"}},{"package":{"name":"org.apache.cassandra:apache-cassandra","ecosystem":"Maven","purl":"pkg:maven/org.apache.cassandra/apache-cassandra"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.1.0"},{"fixed":"2.1.4"}]}],"versions":["2.1.0","2.1.1","2.1.2","2.1.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-w7f2-gjxf-2gm9/GHSA-w7f2-gjxf-2gm9.json"}}],"schema_version":"1.9.0"}