Incorrect Authorization Affecting org.apache.cassandra:cassandra-all package, versions [4.0.0,4.0.16)[4.1-alpha1,4.1.8)[5.0-alpha1,5.0.3)


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.04% (12th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Incorrect Authorization vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JAVA-ORGAPACHECASSANDRA-8688121
  • published5 Feb 2025
  • disclosed4 Feb 2025
  • creditStefan Miklosovic

Introduced: 4 Feb 2025

NewCVE-2025-24860  (opens in a new tab)
CWE-863  (opens in a new tab)

How to fix?

Upgrade org.apache.cassandra:cassandra-all to version 4.0.16, 4.1.8, 5.0.3 or higher.

Overview

org.apache.cassandra:cassandra-all is a maven plugin for the Apache Cassandra Project. Which, develops a highly scalable second-generation distributed database, bringing together Dynamo's fully distributed design and Bigtable's ColumnFamily-based data model.

Affected versions of this package are vulnerable to Incorrect Authorization in cql3/statements/AlterRoleStatement.java, exploitable via CassandraNetworkAuthorizer and CassandraCIDRAuthorizer. A user with limited data center access can upgrade their own permissions via DCL statement, to gain access to unintended datacenter or IP/CIDR groups.

CVSS Scores

version 4.0
version 3.1