Apache Cassandra
cpe:2.3:a:apache:cassandra:*:*:*:*:*:*:*
- >= 4.0, <= 4.0.19
- >= 4.1, <= 4.1.10
- >= 5.0, <= 5.0.6
A denial-of-service vulnerability has been identified in Apache Cassandra versions 4.0 (through 4.0.19), 4.1 (through 4.1.10), and 5.0 (through 5.0.6). This vulnerability allows authenticated users to increase query latencies by repeatedly changing passwords, causing disruption over the Cassandra Query Language (CQL) interface.
Exploitation of this vulnerability leads to increased query latencies, causing a denial-of-service condition for affected users.
Users are advised to upgrade to Apache Cassandra versions 4.0.20, 4.1.11, or 5.0.7, all of which address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.