Privilege Escalation Vulnerability in Apache Cassandra
CVE-2025-23015

8.8HIGH

Key Information:

Vendor
Apache
Vendor
CVE Published:
4 February 2025

Summary

A Privilege Defined With Unsafe Actions vulnerability exists in Apache Cassandra, allowing users with MODIFY permissions on all keyspaces to escalate their privileges to superuser. This can be exploited through unsafe actions to system resources, potentially leading to unauthorized access and data breaches within a targeted Cassandra cluster. Operators are advised to review permissions and access rules associated with data MODIFY privileges to mitigate risks associated with this vulnerability.

Affected Version(s)

Apache Cassandra 3.0.0 <= 3.0.30

Apache Cassandra 3.1.0 <= 3.11.17

Apache Cassandra 4.0.0 <= 4.0.15

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Adam Pond of Apple Services Engineering Security
Ali Mirheidari of Apple Services Engineering Security
Terry Thibault of Apple Services Engineering Security
Will Brattain of Apple Services Engineering Security
.