Re: CVE-2020-13946 Apache Cassandra RMI Rebind Vulnerability

2020-09-11 Thread Jeremiah D Jordan
This vulnerability is only exposed if someone can access your JMX port. If you lock down access to JMX ports then you can avoid it. -Jeremiah > On Sep 2, 2020, at 3:36 AM, Sam Tunnicliffe wrote: > > Hi Manish, > > unfortunately I'm afraid, as far as I'm aware there is not. > > Thanks, > Sam

Re: CVE-2020-13946 Apache Cassandra RMI Rebind Vulnerability

2020-09-02 Thread Sam Tunnicliffe
Hi Manish, unfortunately I'm afraid, as far as I'm aware there is not. Thanks, Sam > On 2 Sep 2020, at 04:14, manish khandelwal > wrote: > > Hi Sam > > Is there any alternative to avoid this vulnerability? Like upgrade to > specific JVM version. > > Regards > Manish > > On Tue, Sep 1, 202

Re: CVE-2020-13946 Apache Cassandra RMI Rebind Vulnerability

2020-09-01 Thread manish khandelwal
Hi Sam Is there any alternative to avoid this vulnerability? Like upgrade to specific JVM version. Regards Manish On Tue, Sep 1, 2020 at 8:03 PM Sam Tunnicliffe wrote: > CVE-2020-13946 Apache Cassandra RMI Rebind Vulnerability > > Versions Affected: > All versions prior to: 2.1.22, 2.2.18, 3.0