Apache Cassandra Users Urged To Upgrade After Vulnerability Disclosed
Shachar Menashe, senior director of security research at JFrog, told ZDNet that even though these new vulnerabilities do not affect Apache Cassandra default installations where User Defined Functions (UDFs) are disabled, many Cassandra configurations enable them, causing the instance to be vulnerable to an RCE or DoS attack. “We recommend looking at your Cassandra configuration and – if UDFs are enabled – take the appropriate steps to remediate,” Menashe said....