CVE-2021-44521 describes a critical remote code execution (RCE) vulnerability in Apache Cassandra when specific, documented-as-unsafe user-defined function (UDF) configurations are enabled. An attacker with sufficient permissions to create UDFs can leverage this to execute arbitrary code on the host. This vulnerability carries a CVSS score of 9.1 (Critical) due to its network-based attack vector, low complexity, and high impact on confidentiality, integrity, and availability. While not listed in the KEV catalog, exploit intelligence indicates the availability of Nuclei templates for exploitation, and it has garnered significant community discussion and media coverage, suggesting active interest in its exploitation potential.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0.0, < 3.0.26CPE matchmatch criteria | cpe:2.3:a:apache:cassandra:*:*:*:*:*:*:*:* | ||
>= 3.11.0, < 3.11.12CPE matchmatch criteria | cpe:2.3:a:apache:cassandra:*:*:*:*:*:*:*:* | ||
>= 4.0.0, < 4.0.2CPE matchmatch criteria | cpe:2.3:a:apache:cassandra:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.7 Bluesky, 0.4 Mastodon, and 1.7 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.