Apache Cassandra
cpe:2.3:a:apache:cassandra:*:*:*:*:*:*:*
- >= 3.0.0, <= 3.0.30
- >= 3.1.0, <= 3.11.17
- >= 4.0.0, <= 4.0.15
- >= 4.1.0, <= 4.1.7
- >= 5.0.0, <= 5.0.2
A vulnerability allowing privilege escalation to superuser has been identified in Apache Cassandra. This issue affects users with MODIFY permission on all keyspaces, who can exploit unsafe actions to a system resource within the targeted Cassandra cluster. The vulnerability is present in Apache Cassandra versions 3.0.0 prior to 3.0.30, 3.1.0 prior to 3.11.17, 4.0.0 prior to 4.0.15, 4.1.0 prior to 4.1.7, and 5.0.0 prior to 5.0.2.
Exploitation of this vulnerability allows unauthorized users to gain superuser privileges, potentially leading to unauthorized access and modification of data within the Cassandra cluster.
Users are advised to upgrade to Apache Cassandra versions 3.0.31, 3.11.18, 4.0.16, 4.1.8, or 5.0.3. NetApp products incorporating Apache Cassandra should refer to the NetApp advisory NTAP-20250214-0006 for guidance.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.