Improper Authorization Vulnerability in Dremio Software
CVE-2025-2298
What is CVE-2025-2298?
An improper authorization flaw in Dremio Software permits authenticated users to delete files they should not have access to, including critical system and cloud-based files. The issue arises from inadequate access controls on a specific API endpoint, allowing any authenticated user to target and remove files beyond their intended permissions. This vulnerability poses significant risks, including potential data loss and Denial of Service (DoS), and could amplify danger depending on the nature of the deleted files.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Dremio Software Linux 24.3.0 <= 24.3.17
Dremio Software Linux 24.3.0 <= 24.3.17
Dremio Software Linux 25.0.0 <= 25.0.15
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
