Cassandra Web 0.5.0 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating path traversal parameters. Attackers can exploit the disabled Rack::Protection module to read sensitive system files like /etc/passwd and retrieve Apache Cassandra database credentials.
Metrics
Affected Vendors & Products
References
History
Tue, 27 Jan 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cassandra Web 0.5.0 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating path traversal parameters. Attackers can exploit the disabled Rack::Protection module to read sensitive system files like /etc/passwd and retrieve Apache Cassandra database credentials. | |
| Title | Cassandra Web 0.5.0 - Remote File Read | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-01-27T15:23:47.357Z
Reserved: 2026-01-25T13:50:01.142Z
Link: CVE-2020-36939
No data.
Status : Received
Published: 2026-01-27T16:16:11.120
Modified: 2026-01-27T16:16:11.120
Link: CVE-2020-36939
No data.
OpenCVE Enrichment
No data.