CVE-2021-44521
CVSS v3
9.1
CRITICAL
EPSS Score
57.5 %
exploit probability, as of 2026-10-04
CISA KEV
No
known exploited
Exploitation
—
SSVC status
Description
When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enable_user_defined_functions_threads: false it is possible for an attacker to execute arbitrary code on the host. The attacker would need to have enough permissions to create user defined functions in the cluster to be able to exploit this. Note that this configuration is documented as unsafe, and will continue to be considered unsafe after this CVE.
Technical details
- Published
- 2022-02-11
Frequently asked questions
What is CVE-2021-44521?
When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enable_user_defined_functions_threads: false it is possible for an attacker to execute arbitrary code on the host. The attacker would need to have enough permissions to create user defined functions in the cluster to be able to exploit this. Note that this configuration is documented as unsafe, and will continue to be considered unsafe after this CVE.
Is CVE-2021-44521 actively exploited?
Active exploitation of CVE-2021-44521 has not been confirmed. Its EPSS score was 57.5% on 2026-10-04, the estimated probability of exploitation in the next 30 days.
What is the CVSS score for CVE-2021-44521?
CVE-2021-44521 has a CVSS v3 base score of 9.1 (CRITICAL severity).
Is CVE-2021-44521 affecting your environment?
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
No credit card required · 50 free checks/month · Free API key
Other 2021 vulnerabilities worth triaging
Ranked by exploit probability (EPSS).