Cassandra Web 0.5.0 contains a directory traversal vulnerability
Published: January 27, 2026
SECURITY IDENTIFIERS
- CVE: CVE-2020-36939 (NVD)
- GHSA: GHSA-8mfv-xhp5-48q9
GEM
SEVERITY
CVSS v3.x: 7.5 (High)
PATCHED VERSIONS
None available.
DESCRIPTION
Cassandra Web 0.5.0 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating path traversal parameters. Attackers can exploit the disabled Rack::Protection module to read sensitive system files like /etc/passwd and retrieve Apache Cassandra database credentials.
RELATED
- https://nvd.nist.gov/vuln/detail/CVE-2020-36939
- https://github.com/avalanche123/cassandra-web/commit/f11e47a26f316827f631d7bcfec14b9dd94f44be#diff-f965f92b425fb2f75d38b491b2625fe21b8af20b7666217546bce8a42b198ea4Prot
- https://www.vulncheck.com/advisories/cassandra-web-remote-file-read
- https://www.exploit-db.com/exploits/49362
- https://github.com/advisories/GHSA-8mfv-xhp5-48q9
