Apache · Apache Cassandra · CVE-2025-23015
**Name of the Vulnerable Software and Affected Versions**
Apache Cassandra versions 3.0.30, 3.11.17, 4.0.15, 4.1.7, 5.0.2
**Description**
A privilege escalation issue exists in Apache Cassandra, where a user with MODIFY permission on all keyspaces can escalate privileges to superuser within a targeted Cassandra cluster via unsafe actions to a system resource. Operators granting data MODIFY permission on all keyspaces on affected versions should review data access rules for potential breaches.
**Recommendations**
To resolve the issue, upgrade to versions 3.0.31, 3.11.18, 4.0.16, 4.1.8, or 5.0.3, which fixes the issue.
Operators should review data access rules for potential breaches.