Privilege Escalation Vulnerability in Apache Cassandra
CVE-2025-23015
What is CVE-2025-23015?
A Privilege Defined With Unsafe Actions vulnerability exists in Apache Cassandra, allowing users with MODIFY permissions on all keyspaces to escalate their privileges to superuser. This can be exploited through unsafe actions to system resources, potentially leading to unauthorized access and data breaches within a targeted Cassandra cluster. Operators are advised to review permissions and access rules associated with data MODIFY privileges to mitigate risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Apache Cassandra 3.0.0 <= 3.0.30
Apache Cassandra 3.1.0 <= 3.11.17
Apache Cassandra 4.0.0 <= 4.0.15
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved