RubySec

Providing security resources for the Ruby community

CVE-2020-36939 (cassandra-web): Cassandra Web 0.5.0 contains a directory traversal vulnerability

Cassandra Web 0.5.0 contains a directory traversal vulnerability

Published: January 27, 2026

SECURITY IDENTIFIERS

GEM

cassandra-web

SEVERITY

CVSS v3.x: 7.5 (High)

PATCHED VERSIONS

None available.

DESCRIPTION

Cassandra Web 0.5.0 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating path traversal parameters. Attackers can exploit the disabled Rack::Protection module to read sensitive system files like /etc/passwd and retrieve Apache Cassandra database credentials.

RELATED