PT-2025-7174 · Stratio+1 · Cassandra-Lucene-Index+1

Jfleming-Ic

·

Published

2025-02-13

·

Updated

2025-02-17

·

CVE-2025-26511

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Instaclustr fork of Stratio's Cassandra-Lucene-Index plugin versions 4.0-rc1-1.0.0 through 4.0.16-1.0.0 Instaclustr fork of Stratio's Cassandra-Lucene-Index plugin versions 4.1.0-1.0.0 through 4.1.8-1.0.0
Description: The vulnerability allows authenticated Cassandra users to remotely bypass Role-Based Access Control (RBAC) and escalate their privileges. This can be exploited when the required conditions are met, including the use of Cassandra 4.x, a vulnerable version of the Cassandra-Lucene-Index plugin, data added to tables, a Lucene index created, and Cassandra flush has run.
Recommendations: For versions 4.0-rc1-1.0.0 through 4.0.16-1.0.0, upgrade to a fixed version of the Cassandra-Lucene-Index plugin. For versions 4.1.0-1.0.0 through 4.1.8-1.0.0, upgrade to a fixed version of the Cassandra-Lucene-Index plugin. As a temporary workaround, consider dropping all Lucene indexes and stopping the use of the plugin to prevent exploitation. Review users in Cassandra to validate all superuser privileges.

Fix

LPE

Incorrect Authorization

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-26511
GHSA-MRQP-Q7VX-V2CX

Affected Products

Apache Cassandra
Cassandra-Lucene-Index