PT-2025-5589 · Apache+1 · Apache Cassandra+1

Stefan Miklosovic

·

Published

2024-02-20

·

Updated

2026-05-18

·

CVE-2025-24860

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache Cassandra versions 4.0.0 through 4.0.15 Apache Cassandra versions 4.1.0 through 4.1.7 Apache Cassandra versions 5.0.0 through 5.0.2
Description The issue allows users to access a datacenter or IP/CIDR groups they should not be able to when using CassandraNetworkAuthorizer or CassandraCIDRAuthorizer. Users with restricted data center access can update their own permissions via data control language (DCL) statements on affected versions. Operators using CassandraNetworkAuthorizer or CassandraCIDRAuthorizer on affected versions should review data access rules for potential breaches.
Recommendations Apache Cassandra versions 4.0.0 through 4.0.15: Upgrade to version 4.0.16 to fix the issue. Apache Cassandra versions 4.1.0 through 4.1.7: Upgrade to version 4.1.8 to fix the issue. Apache Cassandra versions 5.0.0 through 5.0.2: Upgrade to version 5.0.3 to fix the issue. As a temporary workaround, consider reviewing and restricting data access rules to minimize the risk of exploitation.

Fix

LPE

Incorrect Authorization

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

AZL-56433
AZL-56440
BDU:2025-01150
BDU:2025-01159
BIT-CASSANDRA-2025-24860
CLEANSTART-2026-DD05788
CLEANSTART-2026-VH41554
CVE-2025-24860
GHSA-3CJF-FWCQ-XH22

Affected Products

Apache Cassandra
Red Os