A AegiFlow
HIGHCVSS 8.7EPSS 2.6%

CVE-2020-36939

Cassandra Web - Remote File Read

Published
2026-01-27
Modified
2026-09-08
EPSS percentile
84%
Aliases
GHSA-8mfv-xhp5-48q9
Sources
github-advisory

Summary

Cassandra Web 0.5.0 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating path traversal parameters. Attackers can exploit the disabled Rack::Protection module to read sensitive system files like /etc/passwd and retrieve Apache Cassandra database credentials.

Affected packages

EcosystemPackageAffected versionsFixed versions
RubyGemscassandra-web

Remediation: No patched version is listed by GitHub.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.