Security advisory: Pre-authentication RCE in DataStax Enterprise (DSE) 6.8.49 (DataStax)
Posted by disclosure via Fulldisclosure on Aug 170day Rubbish Research Team is publicly disclosing a vulnerability in DataStax Enterprise (DSE) 6.8.49 (DataStax). The
research is published and a proof-of-concept is available. Pre-authentication RCE (CVSS 9.8, pre-authentication) DataStax Enterprise (DSE) 6.8.49 runs a Gremlin Server on WebSocket 8182. The default configuration has the
gremlin_server authentication section commented out, which means TinkerPop's default allowAll...