Incorrect Authorization Affecting org.apache.cassandra:cassandra-all package, versions [4.0.0,4.0.16)[4.1-alpha1,4.1.8)[5.0-alpha1,5.0.3)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
1.07% (62nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGAPACHECASSANDRA-8688121
  • published5 Feb 2025
  • disclosed4 Feb 2025
  • creditStefan Miklosovic

Introduced: 4 Feb 2025

CVE-2025-24860  (opens in a new tab)
CWE-863  (opens in a new tab)

How to fix?

Upgrade org.apache.cassandra:cassandra-all to version 4.0.16, 4.1.8, 5.0.3 or higher.

Overview

org.apache.cassandra:cassandra-all is a maven plugin for the Apache Cassandra Project. Which, develops a highly scalable second-generation distributed database, bringing together Dynamo's fully distributed design and Bigtable's ColumnFamily-based data model.

Affected versions of this package are vulnerable to Incorrect Authorization in cql3/statements/AlterRoleStatement.java, exploitable via CassandraNetworkAuthorizer and CassandraCIDRAuthorizer. A user with limited data center access can upgrade their own permissions via DCL statement, to gain access to unintended datacenter or IP/CIDR groups.

CVSS Base Scores

version 4.0
version 3.1