Cleartext transmission of sensitive information in Cassandra - CVE-2020-17516
Published: February 2, 2021
Cassandra
Apache Foundation
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to software uses insecure communication channel to transmit sensitive information when using "dc" or "rack" internode_encryption setting. A remote attacker can use unencrypted connection despite not being in the same rack or dc, and bypass mutual TLS requirement.