Cassandra Web - Remote File Read
High severity
GitHub Reviewed
Published
Jan 27, 2026
to the GitHub Advisory Database
•
Updated Sep 8, 2026
Description
Published by the National Vulnerability Database
Jan 27, 2026
Published to the GitHub Advisory Database
Jan 27, 2026
Reviewed
Sep 8, 2026
Last updated
Sep 8, 2026
Cassandra Web 0.5.0 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating path traversal parameters. Attackers can exploit the disabled Rack::Protection module to read sensitive system files like /etc/passwd and retrieve Apache Cassandra database credentials.
References