Описание
Privilege Defined With Unsafe Actions vulnerability in Apache Cassandra. An user with MODIFY permission ON ALL KEYSPACES can escalate privileges to superuser within a targeted Cassandra cluster via unsafe actions to a system resource. Operators granting data MODIFY permission on all keyspaces on affected versions should review data access rules for potential breaches.
This issue affects Apache Cassandra through 3.0.30, 3.11.17, 4.0.15, 4.1.7, 5.0.2.
Users are recommended to upgrade to versions 3.0.31, 3.11.18, 4.0.16, 4.1.8, 5.0.3, which fixes the issue.
A flaw was found in Apache Cassandra. This vulnerability allows a user with MODIFY permission ON ALL KEYSPACES to escalate privileges to a superuser within a targeted Cassandra cluster via unsafe actions to a system resource. Operators granting data MODIFY permission on all keyspaces on affected versions should review data access rules for potential breaches.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| A-MQ Clients 2 | org.apache.cassandra/cassandra-all | Not affected | ||
| Red Hat Data Grid 8 | org.apache.cassandra/cassandra-all | Will not fix | ||
| Red Hat Fuse 7 | org.apache.cassandra/cassandra-all | Out of support scope | ||
| Red Hat Integration Camel K 1 | org.apache.cassandra/cassandra-all | Will not fix | ||
| Red Hat JBoss Data Grid 7 | org.apache.cassandra/cassandra-all | Out of support scope | ||
| Red Hat JBoss Enterprise Application Platform 7 | cassandra-all | Not affected | ||
| Red Hat JBoss Enterprise Application Platform 8 | cassandra-all | Not affected | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | org.apache.cassandra/cassandra-all | Not affected | ||
| streams for Apache Kafka | org.apache.cassandra/cassandra-all | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
5.5 Medium
CVSS3
Связанные уязвимости
Privilege Defined With Unsafe Actions vulnerability in Apache Cassandra. An user with MODIFY permission ON ALL KEYSPACES can escalate privileges to superuser within a targeted Cassandra cluster via unsafe actions to a system resource. Operators granting data MODIFY permission on all keyspaces on affected versions should review data access rules for potential breaches. This issue affects Apache Cassandra through 3.0.30, 3.11.17, 4.0.15, 4.1.7, 5.0.2. Users are recommended to upgrade to versions 3.0.31, 3.11.18, 4.0.16, 4.1.8, 5.0.3, which fixes the issue.
Privilege Defined With Unsafe Actions vulnerability in Apache Cassandr ...
Apache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actions
Уязвимость распределённой системы управления базами данных Apache Cassandra, связанная с небезопасным управлением привилегиями, позволяющая нарушителю повысить свои привилегии
EPSS
5.5 Medium
CVSS3