Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-26467

Опубликовано: 25 авг. 2025
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

Privilege Defined With Unsafe Actions vulnerability in Apache Cassandra. An user with MODIFY permission ON ALL KEYSPACES can escalate privileges to superuser within a targeted Cassandra cluster via unsafe actions to a system resource. Operators granting data MODIFY permission on all keyspaces on affected versions should review data access rules for potential breaches. This issue affects Apache Cassandra 3.0.30, 3.11.17, 4.0.16, 4.1.7, 5.0.2, but this advisory is only for 4.0.16 because the fix to CVE-2025-23015 was incorrectly applied to 4.0.16, so that version is still affected. Users in the 4.0 series are recommended to upgrade to version 4.0.17 which fixes the issue. Users from 3.0, 3.11, 4.1 and 5.0 series should follow recommendation from CVE-2025-23015.

A Privilege Defined With Unsafe Actions vulnerability exists in Apache Cassandra. In affected versions, a user with MODIFY permission on all keyspaces can exploit unsafe operations against certain system resources to escalate privileges and gain superuser access within the Cassandra cluster. This escalation is possible because granting MODIFY at the global keyspace level inadvertently extends to sensitive resources, allowing abuse beyond the intended scope of data modification privileges.

Отчет

This vulnerability is rated Moderate because exploitation requires an attacker to already have MODIFY permission on all keyspaces. While it allows privilege escalation to superuser within the cluster, it cannot be exploited by unauthenticated users or those with lower privileges. Proper access controls and role management reduce the risk, limiting the impact to clusters where broad MODIFY permissions have been granted.

Меры по смягчению последствий

No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Data Grid 8cassandra-allFix deferred
Red Hat Fuse 7cassandra-allFix deferred
Red Hat JBoss Enterprise Application Platform 7cassandra-allFix deferred
Red Hat JBoss Enterprise Application Platform 8cassandra-allFix deferred
Red Hat JBoss Enterprise Application Platform Expansion Packcassandra-allFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-267
https://bugzilla.redhat.com/show_bug.cgi?id=2390786org.apache.cassandra:cassandra-all: Apache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actions (4.0.16 only)

EPSS

Процентиль: 7%
0.00032
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
21 день назад

Privilege Defined With Unsafe Actions vulnerability in Apache Cassandra. An user with MODIFY permission ON ALL KEYSPACES can escalate privileges to superuser within a targeted Cassandra cluster via unsafe actions to a system resource. Operators granting data MODIFY permission on all keyspaces on affected versions should review data access rules for potential breaches. This issue affects Apache Cassandra 3.0.30, 3.11.17, 4.0.16, 4.1.7, 5.0.2, but this advisory is only for 4.0.16 because the fix to CVE-2025-23015 was incorrectly applied to 4.0.16, so that version is still affected. Users in the 4.0 series are recommended to upgrade to version 4.0.17 which fixes the issue. Users from 3.0, 3.11, 4.1 and 5.0 series should follow recommendation from CVE-2025-23015.

CVSS3: 8.8
debian
21 день назад

Privilege Defined With Unsafe Actions vulnerability in Apache Cassandr ...

CVSS3: 8.8
github
20 дней назад

Apache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actions (4.0.16 only)

CVSS3: 5.5
fstec
7 месяцев назад

Уязвимость распределённой системы управления базами данных Apache Cassandra, связанная с неправильной обработка привилегий, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 7%
0.00032
Низкий

5.5 Medium

CVSS3