CVE-2025-24860 Details
Description
Incorrect Authorization vulnerability in Apache Cassandra allowing users to access a datacenter or IP/CIDR groups they should not be able to when using CassandraNetworkAuthorizer or CassandraCIDRAuthorizer. Users with restricted data center access can update their own permissions via data control language (DCL) statements on affected versions. This issue affects Apache Cassandra: from 4.0.0 through 4.0.15 and from 4.1.0 through 4.1.7 for CassandraNetworkAuthorizer, and from 5.0.0 through 5.0.2 for both CassandraNetworkAuthorizer and CassandraCIDRAuthorizer. Operators using CassandraNetworkAuthorizer or CassandraCIDRAuthorizer on affected versions should review data access rules for potential breaches. Users are recommended to upgrade to versions 4.0.16, 4.1.8, 5.0.3, which fixes the issue.
A vulnerability has been identified in Apache Cassandra that allows users to bypass authorization and access datacenters or IP/CIDR groups they should not be able to. This issue arises when using the CassandraNetworkAuthorizer or CassandraCIDRAuthorizer. Affected users with restricted datacenter access can manipulate their own permissions through data control language (DCL) statements. The vulnerability is present in Apache Cassandra versions 4.0.0 to 4.0.15, 4.1.0 to 4.1.7, and 5.0.0 to 5.0.2.
Users are advised to upgrade to Apache Cassandra versions 4.0.16, 4.1.8, or 5.0.3, which address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 6, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.netapp.com/advisory/ntap-20250214-0005/ | CVE | Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2025/02/03/3 | CVE | Mailing ListVendor Advisory |
| https://lists.apache.org/thread/yjo5on4tf7s1r9qklc4byrz30b8vkm2d | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache cassandra | >= 4.0.0, < 4.0.16 >= 4.1.0, < 4.1.8 >= 5.0.0, < 5.0.3 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 9, 2025 | Initial Analysis | [email protected] |
| Feb 15, 2025 | CVE Modified | CVE |
| Feb 6, 2025 | CVE Modified | CISA-ADP |
| Feb 4, 2025 | New CVE Received | [email protected] |
| Feb 4, 2025 | CVE Modified | CVE |