PT-2025-2395 · Apache+1 · Apache Cassandra+1

·

CVE-2024-27137

·

Published

2024-02-20

·

Updated

2026-05-18

CVSS v3.1

5.3

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Apache Cassandra versions 4.0.2 through 5.0.2
Description A local attacker without access to the Apache Cassandra process or configuration files can manipulate the RMI registry to perform a man-in-the-middle attack. This allows the attacker to capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and perform unauthorized operations.
Recommendations Apache Cassandra versions 4.0.2 through 5.0.2: Upgrade to a release equal to or later than 4.0.15, 4.1.8, or 5.0.3 to fix the issue.

Exploit

Fix

DoS

Exposure of Resource to Wrong Sphere

Improper Authentication

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-56430
AZL-56446
BDU:2025-01150
BIT-CASSANDRA-2024-27137
CLEANSTART-2026-CI66802
CLEANSTART-2026-DD05788
CLEANSTART-2026-KM27583
CLEANSTART-2026-SP91806
CLEANSTART-2026-VH41554
CVE-2024-27137
GHSA-RGFX-7P65-3FF4

Affected Products

Apache Cassandra
Red Os