CVE-2025-26467
- EPSS 0.05%
- Veröffentlicht 25.08.2025 14:15:30
- Zuletzt bearbeitet 26.08.2025 21:14:41
Privilege Defined With Unsafe Actions vulnerability in Apache Cassandra. An user with MODIFY permission ON ALL KEYSPACES can escalate privileges to superuser within a targeted Cassandra cluster via unsafe actions to a system resource. Operators grant...
CVE-2025-26511
- EPSS 0.06%
- Veröffentlicht 13.02.2025 16:16:50
- Zuletzt bearbeitet 14.02.2025 00:15:07
Systems running the Instaclustr fork of Stratio's Cassandra-Lucene-Index plugin versions 4.0-rc1-1.0.0 through 4.0.16-1.0.0 and 4.1.2-1.0.0 through 4.1.8-1.0.0, installed into Apache Cassandra version 4.x, are susceptible to a vulnerability which ...
CVE-2025-24860
- EPSS 0.09%
- Veröffentlicht 04.02.2025 11:15:09
- Zuletzt bearbeitet 09.06.2025 19:43:36
Incorrect Authorization vulnerability in Apache Cassandra allowing users to access a datacenter or IP/CIDR groups they should not be able to when using CassandraNetworkAuthorizer or CassandraCIDRAuthorizer. Users with restricted data center access c...
CVE-2024-27137
- EPSS 0.05%
- Veröffentlicht 04.02.2025 11:15:08
- Zuletzt bearbeitet 14.07.2025 12:43:12
In Apache Cassandra it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry to perform a man-in-the-middle attack and capture user names and passwords used to access ...
CVE-2025-23015
- EPSS 0.26%
- Veröffentlicht 04.02.2025 10:15:09
- Zuletzt bearbeitet 14.07.2025 12:44:57
Privilege Defined With Unsafe Actions vulnerability in Apache Cassandra. An user with MODIFY permission ON ALL KEYSPACES can escalate privileges to superuser within a targeted Cassandra cluster via unsafe actions to a system resource. Operators grant...
CVE-2023-30601
- EPSS 0.02%
- Veröffentlicht 30.05.2023 08:15:10
- Zuletzt bearbeitet 21.11.2024 08:00:28
Privilege escalation when enabling FQL/Audit logs allows user with JMX access to run arbitrary commands as the user running Apache Cassandra This issue affects Apache Cassandra: from 4.0.0 through 4.0.9, from 4.1.0 through 4.1.1. WORKAROUND The vuln...
CVE-2021-44521
- EPSS 91.53%
- Veröffentlicht 11.02.2022 13:15:07
- Zuletzt bearbeitet 21.11.2024 06:31:09
When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enable_user_defined_functions_threads: false it is possible for an attacker to execute arbitrary code on ...
CVE-2020-17516
- EPSS 0.85%
- Veröffentlicht 03.02.2021 17:15:13
- Zuletzt bearbeitet 21.11.2024 05:08:16
Apache Cassandra versions 2.1.0 to 2.1.22, 2.2.0 to 2.2.19, 3.0.0 to 3.0.23, and 3.11.0 to 3.11.9, when using 'dc' or 'rack' internode_encryption setting, allows both encrypted and unencrypted internode connections. A misconfigured node or a maliciou...
CVE-2020-13946
- EPSS 0.23%
- Veröffentlicht 01.09.2020 21:15:11
- Zuletzt bearbeitet 21.11.2024 05:02:12
In Apache Cassandra, all versions prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2, it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry to perform a man-in-the-...
CVE-2019-2684
- EPSS 1.29%
- Veröffentlicht 23.04.2019 19:32:55
- Zuletzt bearbeitet 21.11.2024 04:41:21
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Difficult to exploit vulnerability allows unauthen...