CVE-2026-32588
- EPSS 0.1%
- Veröffentlicht 07.04.2026 16:42:52
- Zuletzt bearbeitet 15.04.2026 15:45:40
Authenticated DoS over CQL in Apache Cassandra 4.0, 4.1, 5.0 allows authenticated user to raise query latencies via repeated password changes. Users are recommended to upgrade to version 4.0.20, 4.1.11, 5.0.7, which fixes this issue.
CVE-2026-27315
- EPSS 0.02%
- Veröffentlicht 07.04.2026 16:40:51
- Zuletzt bearbeitet 15.04.2026 15:47:57
Sensitive Information Leak in cqlsh in Apache Cassandra 4.0 allows access to sensitive information, like passwords, from previously executed cqlsh command via ~/.cassandra/cqlsh_history local file access. Users are recommended to upgrade to version...
CVE-2026-27314
- EPSS 0.05%
- Veröffentlicht 07.04.2026 16:33:44
- Zuletzt bearbeitet 15.04.2026 15:48:53
Privilege escalation in Apache Cassandra 5.0 on an mTLS environment using MutualTlsAuthenticator allows a user with only CREATE permission to associate their own certificate identity with an arbitrary role, including a superuser role, and authenticat...
CVE-2025-26467
- EPSS 0.07%
- Veröffentlicht 25.08.2025 14:15:30
- Zuletzt bearbeitet 26.08.2025 21:14:41
Privilege Defined With Unsafe Actions vulnerability in Apache Cassandra. An user with MODIFY permission ON ALL KEYSPACES can escalate privileges to superuser within a targeted Cassandra cluster via unsafe actions to a system resource. Operators grant...
CVE-2025-26511
- EPSS 0.03%
- Veröffentlicht 13.02.2025 16:16:50
- Zuletzt bearbeitet 15.04.2026 00:35:42
Systems running the Instaclustr fork of Stratio's Cassandra-Lucene-Index plugin versions 4.0-rc1-1.0.0 through 4.0.16-1.0.0 and 4.1.2-1.0.0 through 4.1.8-1.0.0, installed into Apache Cassandra version 4.x, are susceptible to a vulnerability which ...
CVE-2025-24860
- EPSS 0.16%
- Veröffentlicht 04.02.2025 11:15:09
- Zuletzt bearbeitet 09.06.2025 19:43:36
Incorrect Authorization vulnerability in Apache Cassandra allowing users to access a datacenter or IP/CIDR groups they should not be able to when using CassandraNetworkAuthorizer or CassandraCIDRAuthorizer. Users with restricted data center access c...
CVE-2024-27137
- EPSS 0.11%
- Veröffentlicht 04.02.2025 11:15:08
- Zuletzt bearbeitet 14.07.2025 12:43:12
In Apache Cassandra it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry to perform a man-in-the-middle attack and capture user names and passwords used to access ...
CVE-2025-23015
- EPSS 0.41%
- Veröffentlicht 04.02.2025 10:15:09
- Zuletzt bearbeitet 14.07.2025 12:44:57
Privilege Defined With Unsafe Actions vulnerability in Apache Cassandra. An user with MODIFY permission ON ALL KEYSPACES can escalate privileges to superuser within a targeted Cassandra cluster via unsafe actions to a system resource. Operators grant...
CVE-2023-30601
- EPSS 0.02%
- Veröffentlicht 30.05.2023 08:15:10
- Zuletzt bearbeitet 21.11.2024 08:00:28
Privilege escalation when enabling FQL/Audit logs allows user with JMX access to run arbitrary commands as the user running Apache Cassandra This issue affects Apache Cassandra: from 4.0.0 through 4.0.9, from 4.1.0 through 4.1.1. WORKAROUND The vuln...
CVE-2021-44521
- EPSS 91.01%
- Veröffentlicht 11.02.2022 13:15:07
- Zuletzt bearbeitet 21.11.2024 06:31:09
When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enable_user_defined_functions_threads: false it is possible for an attacker to execute arbitrary code on ...