Skip to content
Back to skills

Cis Cassandra41 3.5

ASecurity

Ensure that Cassandra only listens for network connections on authorized interfaces

  • 2,182 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added May 30, 2026
securitygonode

Security analysis

A100/100

Scanned May 30, 2026

npx -y skills add CyberStrikeus/CyberStrike --skill cis-cassandra41-3.5 --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Cis Cassandra41 3.5?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Cis Cassandra41 3.5
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/cyberstrikeus-cis-cassandra41-3-5/badge)](https://www.skillsdirectory.com/skills/cyberstrikeus-cis-cassandra41-3-5)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: cis-cassandra41-3.5
description: "Ensure that Cassandra only listens for network connections on authorized interfaces"
category: cis-cassandra
version: "1.0.0"
author: cyberstrike-official
tags: [cis, cassandra, access-control, network, firewall, interfaces]
cis_id: "3.5"
cis_benchmark: "CIS Apache Cassandra 4.1 Benchmark v1.0.0"
tech_stack: [cassandra]
cwe_ids: []
chains_with: []
prerequisites: []
severity_boost: {}
---

# 3.5 Ensure that Cassandra only listens for network connections on authorized interfaces

## Profile Applicability

- Level 1 - Cassandra on Linux

## Description

When `listen_address` is blank and `listen_interface` is commented out, this will be set automatically by `InetAddress.getLocalHost()`. Presuming the node is configured correctly, e.g. hostname, name resolution, etc., this will configure the node to use the address associated with the hostname. The `listen_address` must not be set to `0.0.0.0`.

## Rationale

Setting the address or interface to bind to will tell other Cassandra nodes to which address or interface to connect. This must be changed from the default in order for multiple nodes to be able to communicate.

## Audit

Check the value of `listen_address` or `listen_interface` in the `cassandra.yaml`. If `listen_address` is set `0.0.0.0` or a non-authorized address or interface is specified, this is a finding.

## Remediation

Set the `listen_address` or `listen_interface`, not both, in the `cassandra.yaml` to an authorized address or interface.

## Default Value

```
listen_address: localhost

listen_interface: eth0
```

but is commented out by default.

## References

1. http://cassandra.apache.org/doc/3.11/configuration/cassandra_config_file.html#listen-address
2. http://cassandra.apache.org/doc/3.11/configuration/cassandra_config_file.html#listen-interface

## CIS Controls

**v8:**

- 4.4 Implement and Manage a Firewall on Servers
  - Implement and manage a firewall on servers, where supported. Example implementations include a virtual firewall, operating system firewall, or a third-party firewall agent.

**v7:**

- 9.2 Ensure Only Approved Ports, Protocols and Services Are Running
  - Ensure that only network ports, protocols, and services listening on a system with validated business needs, are running on each system.

## Profile

- Level 1 | Manual

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…