Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-14703
HistoryFeb 15, 2022 - 12:00 a.m.

Apache Cassandra Code Injection Vulnerability

2022-02-1500:00:00
China National Vulnerability Database
www.cnvd.org.cn
24
apache
cassandra
code injection
vulnerability
distributed database
nosql
apache foundation
network system
product
filter
external input data
attacker
execute arbitrary code
host
configurations
cnvd

EPSS

0.053

Percentile

93.2%

A code injection vulnerability exists in Apache Cassandra, a distributed Nosql database from the Apache Foundation, which stems from the failure of a network system or product to properly filter special elements in code segments constructed from external input data. An attacker could exploit this vulnerability to potentially execute arbitrary code on the host in certain configurations.