Severity
5.4MEDIUM
EPSS
0.2%
top 56.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 4

Description

Incorrect Authorization vulnerability in Apache Cassandra allowing users to access a datacenter or IP/CIDR groups they should not be able to when using CassandraNetworkAuthorizer or CassandraCIDRAuthorizer. Users with restricted data center access can update their own permissions via data control language (DCL) statements on affected versions. This issue affects Apache Cassandra: from 4.0.0 through 4.0.15 and from 4.1.0 through 4.1.7 for CassandraNetworkAuthorizer, and from 5.0.0 through 5.0.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.5

Affected Packages3 packages

NVDapache/cassandra4.0.04.0.16+2
Mavenorg.apache.cassandra:cassandra-all4.0-alpha14.0.16+2
CVEListV5apache_software_foundation/apache_cassandra4.0.04.0.15+2

🔴Vulnerability Details

3
GHSA
Apache Cassandra: CassandraNetworkAuthorizer and CassandraCIDRAuthorizer can be bypassed allowing access to different network regions2025-02-04
CVEList
Apache Cassandra: CassandraNetworkAuthorizer and CassandraCIDRAuthorizer can be bypassed allowing access to different network regions2025-02-04
OSV
Apache Cassandra: CassandraNetworkAuthorizer and CassandraCIDRAuthorizer can be bypassed allowing access to different network regions2025-02-04

📋Vendor Advisories

2
Red Hat
org.apache.cassandra:cassandra-all: Apache Cassandra: CassandraNetworkAuthorizer and CassandraCIDRAuthorizer can be bypassed allowing access to different network regions2025-02-04
Microsoft
Race condition vulnerability in Linux kernel bluetooth driver in {minmax}_key_size_set()2024-02-13
CVE-2025-24860 (MEDIUM CVSS 5.4) | Incorrect Authorization vulnerabili | cvebase.io