# Security Advisory: CVE-2021-44521

[Blog](/blog/)&gt;[Technology](/blog/category/technical/)&gt;Security Advisory: CVE-2021-44521 

Security Advisory: CVE-2021-44521
=================================

February 24, 2022 | By [ Instaclustr ](https://www.instaclustr.com/blog/author/instaclustr/)

 

 

 

 



   [ ](https://x.com/intent/tweet?text=Security%20Advisory:%20CVE-2021-44521&url=https://www.instaclustr.com/blog/security-advisory-cve-2021-44521/) [ ](https://www.linkedin.com/shareArticle?mini=true&url=https://www.instaclustr.com/blog/security-advisory-cve-2021-44521/&title=&summary=Security%20Advisory:%20CVE-2021-44521&source=) 

On Friday, February 11, 2022, Instaclustr was advised that a new CVE for Apache Cassandra® had been published. This CVE affects users that have User Defined Functions (UDF) enabled with certain configurations. Instaclustr investigated our configurations and has confirmed that this CVE does not affect our services as we do not have UDF enabled. Self-hosted users are urged to double-check their configuration and modify them accordingly or update as advised below. Please note that upgrading Cassandra mitigates this specific CVE but this configuration is still considered to be unsafe.

If you have any queries regarding this vulnerability and how it relates to Instaclustr services, please contact <security@instaclustr.com>

Advisory for CVE-2021-44521:

When running Apache Cassandra with any of the following configurations

- enable\_user\_defined\_functions: true
- enable\_scripted\_user\_defined\_functions: true
- enable\_user\_defined\_functions\_threads: false

it is possible for an attacker to execute arbitrary code on the host. The attacker would need to have enough permissions to create user-defined functions in the cluster to be able to exploit this. Note that this configuration is documented as unsafe, and will continue to be considered unsafe after this CVE.

This issue is being tracked as CASSANDRA-17352

### **Mitigation:**

Set enable\_user\_defined\_functions\_threads: true (this is default)

or

- 3.0 users should upgrade to 3.0.26
- 3.11 users should upgrade to 3.11.12
- 4.0 users should upgrade to 4.0.2

*Credit: This issue was discovered by Omer Kaspi of the JFrog Security vulnerability research team.*

Need help with your Apache Cassandra database? Discover Instaclustr’s managed service.

[Learn more ](/platform/managed-apache-cassandra/)

 

 

 

 [ Add Instaclustr as a preferred source on Google ](https://google.com/preferences/source?q=instaclustr.com)



 

 ![mail icon]()#### Get the latest articles for open sourceIn your inbox

 <a class="btn btn-primary btn-popup text-dark" href="">Sign up now</a> 

 

 

 

  ### Related content

 [ Zero Downtime Migration to Instaclustr 

 

 Yes, we can migrate existing Cassandra clusters to Instaclustr without any downtime. Here's what to expect from the process... 

 

 

 

 

 

 

 ](https://www.instaclustr.com/blog/zero-downtime-migration-to-instaclustr/) 

 [ Workflow Comparison: Uber Cadence vs Netflix Conductor 

 

 When choosing what’s right for your company’s opensource workflow needs it is important to know the difference and similarities ... 

 

 

 

 

 

 

 ](https://www.instaclustr.com/blog/workflow-comparison-uber-cadence-vs-netflix-conductor/) 

 [ Will Your Cassandra Database Project Succeed?: The New Stack 

 

 Open source Apache Cassandra® continues to stand out as an enterprise-proven solution for organizations seeking high availability... 

 

 

 

 

 

 

 ](https://www.instaclustr.com/blog/will-your-cassandra-database-project-succeed-the-new-stack/) 

 

  <a class="close-modal" href="">×</a>Sign upto ourNewsletter
-----------------------
