GHSA-8ffc-79xg-29w8 · Severity: critical · Ecosystem: maven — Apache Cassandra vulnerable to Code Injection due to unsafe configuration
When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enable_user_defined_functions_threads: false it is possible for an attacker to execute arbitrary code on the host. The attacker would need to have enough permissions to create user defined functions in the cluster to be able to exploit this. Note that this configuration is documented as unsafe, and will continue to be considered unsafe after this CVE.
Conclusion & alert: CVE-2021-44521 is rated High Exploit Risk (81/100): CVSS Critical severity, with high exploitation likelihood (EPSS 54.89%, 99th percentile). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 91.01% | 54.89% | -36.12% |
| 2 | 2026-04-23 | 90.61% | 91.01% | +0.39% |
| 3 | 2026-02-28 | — | 90.61% | — |
Full EPSS history (48 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.1 | 3.1 | CRITICAL |
|
2.3 | 6.0 | [email protected] |
| 8.5 | 2.0 | HIGH |
|
6.8 | 10.0 | [email protected] |
GHSA-8ffc-79xg-29w8 · Severity: critical · Ecosystem: maven — Apache Cassandra vulnerable to Code Injection due to unsafe configuration
| vendor | priority | summary | link |
|---|---|---|---|
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2021-44521 |
suse
|
high | CVE-2021-44521 severity important: SUSE including 2 source package names (cassandra, cassandra-tools), 10 product×package rows across 5 product lines (HPE Helion OpenStack 8, SUSE OpenStack Cloud 8, … (5 product lines)): Known Not Affected 10. | https://www.suse.com/security/cve/CVE-2021-44521/ |
| URL | Tags |
|---|---|
| http://www.openwall.com/lists/oss-security/2022/02/11/4 | Mailing List Third Party Advisory |
| https://jfrog.com/blog/cve-2021-44521-exploiting-apache-cassandra-user-defined-functions-for-remote-code-execution/ | Exploit Mitigation Third Party Advisory |
| https://lists.apache.org/thread/y4nb9s4co34j8hdfmrshyl09lokm7356 | Issue Tracking Mailing List Vendor Advisory |
| https://security.netapp.com/advisory/ntap-20220225-0001/ | Third Party Advisory |