Cassandra Web 0.5.0 Remote File Read...

- AV AC AU C I A
发布: 2020-12-29
修订: 2025-04-13

Cassandra Web is vulnerable to directory traversal due to the disabled Rack::Protection module. Apache Cassandra credentials are passed via the CLI in order for the server to auth to it and provide the web access, so they are also one thing that can be captured via the arbitrary file read. Version 0.5.0 is affected.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息