VDB
Sign up
HIGH7.5

GHSA-8mfv-xhp5-48q9

Cassandra Web - Remote File Read

Details

Cassandra Web 0.5.0 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating path traversal parameters. Attackers can exploit the disabled Rack::Protection module to read sensitive system files like /etc/passwd and retrieve Apache Cassandra database credentials.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/cassandra-web
Introduced in: 0

No fixed version published yet for cassandra-web (bundler). Pin to a known-safe version or switch to an alternative.

References