Improper Authorization Vulnerability in Dremio Software
CVE-2025-2298

8.4HIGH

Key Information:

Vendor
CVE Published:
21 April 2025

What is CVE-2025-2298?

An improper authorization flaw in Dremio Software permits authenticated users to delete files they should not have access to, including critical system and cloud-based files. The issue arises from inadequate access controls on a specific API endpoint, allowing any authenticated user to target and remove files beyond their intended permissions. This vulnerability poses significant risks, including potential data loss and Denial of Service (DoS), and could amplify danger depending on the nature of the deleted files.

Affected Version(s)

Dremio Software Linux 24.3.0 <= 24.3.17

Dremio Software Linux 24.3.0 <= 24.3.17

Dremio Software Linux 25.0.0 <= 25.0.15

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Marc Olivier Bergeron (GoSecure.ai)
.
CVE-2025-2298 : Improper Authorization Vulnerability in Dremio Software