CVE-2025-23015
Privilege Defined With Unsafe Actions vulnerability in Apache Cassandra. An user with MODIFY permission ON ALL KEYSPACES can escalate privileges to superuser within a targeted Cassandra cluster via unsafe actions to a system resource. Operators granting data MODIFY permission on all keyspaces on affected versions should review data access rules for potential breaches. This issue affects Apache Cassandra through 3.0.30, 3.11.17, 4.0.15, 4.1.7, 5.0.2. Users are recommended to upgrade to versions 3.0.31, 3.11.18, 4.0.16, 4.1.8, 5.0.3, which fixes the issue.
- Affected products
- Apache Cassandra
- Apache Cassandra
- < 3.0.31, 3.11.18, 4.0.16, 4.1.8, 5.0.3
- Fix
- Available
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 1.0% (58th percentile)
- Weakness
- CWE-267
- NVD status
- Analyzed
- Published
- 2025-02-04
No indexed exploits for CVE-2025-23015 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2025-23015 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.