+dev@cassandra.apache.org

---------- Forwarded message ---------
From: Paulo Motta <pa...@apache.org>
Date: Mon, Feb 3, 2025 at 6:20 PM
Subject: CVE-2025-24860: Apache Cassandra: CassandraNetworkAuthorizer
and CassandraCIDRAuthorizer can be bypassed allowing access to
different network regions
To: <annou...@apache.org>, <u...@cassandra.apache.org>


Severity: moderate

Affected versions:

- Apache Cassandra 4.0.0 through 4.0.15
- Apache Cassandra 4.1.0 through 4.1.7
- Apache Cassandra 5.0.0 through 5.0.2

Description:

Incorrect Authorization vulnerability in Apache Cassandra allowing
users to access a datacenter or IP/CIDR groups they should not be able
to when using CassandraNetworkAuthorizer or CassandraCIDRAuthorizer.

Users with restricted data center access can update their own
permissions via data control language (DCL) statements on affected
versions.




This issue affects Apache Cassandra: from 4.0.0 through 4.0.15 and
from 4.1.0 through 4.1.7 for CassandraNetworkAuthorizer, and from
5.0.0 through 5.0.2 for both CassandraNetworkAuthorizer and
CassandraCIDRAuthorizer.




Operators using CassandraNetworkAuthorizer or CassandraCIDRAuthorizer
on affected versions should review data access rules for potential
breaches. Users are recommended to upgrade to versions 4.0.16, 4.1.8,
5.0.3, which fixes the issue.

This issue was reported by Stefan Miklosovic

References:

https://cassandra.apache.org/
https://www.cve.org/CVERecord?id=CVE-2025-24860

Reply via email to