Feed/CVE-2020-36939
CVE-2020-36939HIGHCVSS 7.5

CVE-2020-36939

Published Jan 27, 2026·Updated Sep 8, 2026

NVD Description

Cassandra Web 0.5.0 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating path traversal parameters. Attackers can exploit the disabled Rack::Protection module to read sensitive system files like /etc/passwd and retrieve Apache Cassandra database credentials.

Affected Packages (1)

cassandra-webGEM
Fixed in = 0.5.0

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free