PatchSiren

avalanche123 CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH avalanche123 CVE published 2026-01-27

CVE-2020-36939

Cassandra Web 0.5.0 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating path traversal parameters. This vulnerability can lead to sensitive information disclosure and potentially allow attackers to retrieve Apache Cassandra database credentials. Defenders should assess exposure and prioritize remediation to prevent exploitation. The CV [truncated]