#VU60551 Security features bypass in Cassandra - CVE-2021-44521
Published: February 11, 2022 / Updated: November 26, 2022
Cassandra
Apache Foundation
Description
The vulnerability allows a remote user to execute arbitrary code on the system.
The vulnerability exists due to insecure configuration that allows arbitrary code execution if the following settings are applied:
enable_user_defined_functions: true
enable_scripted_user_defined_functions: true
enable_user_defined_functions_threads: false
Note, such configuration is considered insecure and as not default.