CVE-2024-27137: Apache Cassandra: unrestricted deserialization of JMX authentication credentials

2025-02-03 Thread Paulo Motta
Severity: moderate Affected versions: - Apache Cassandra 4.0.2 before 4.0.15 - Apache Cassandra 4.1.0 before 4.1.8 - Apache Cassandra 5.0-beta1 before 5.0.3 Description: In Apache Cassandra it is possible for a local attacker without access to the Apache Cassandra process or configuration file

Re: JMX authentication

2010-10-12 Thread Jonathan Ellis
nodetool does not support authentication. On Tue, Oct 12, 2010 at 10:17 AM, Henry Luo wrote: > Can you turn JMX authentication on for Cassandra? I tried and it works for > jconsole, etc. But I couldn’t figure out how to pass username/password to > nodetool, etc. > > > >

JMX authentication

2010-10-12 Thread Henry Luo
Can you turn JMX authentication on for Cassandra? I tried and it works for jconsole, etc. But I couldn't figure out how to pass username/password to nodetool, etc. Anyone has tried it before? Thanks. Henry The information transmitted is intended only fo