Security advisory: Pre-authent... Note

Security advisory: Pre-authentication RCE in DataStax Enterprise (DSE) 6.8.49 (DataStax)

Posted by disclosure via Fulldisclosure on Aug 170day Rubbish Research Team is publicly disclosing a vulnerability in DataStax Enterprise (DSE) 6.8.49 (DataStax). The research is published and a proof-of-concept is available. Pre-authentication RCE (CVSS 9.8, pre-authentication) DataStax Enterprise (DSE) 6.8.49 runs a Gremlin Server on WebSocket 8182. The default configuration has the gremlin_server authentication section commented out, which means TinkerPop's default allowAll...