Systems running the Instaclustr fork of Stratio's Cassandra-Lucene-Index plugin versions 4.0-rc1-1.0.0 through 4.0.16-1.0.0 and 4.1.2-1.0.0 through 4.1.8-1.0.0, installed into Apache Cassandra version 4.x, are susceptible to a vulnerability which when successfully exploited could allow authenticated Cassandra users to remotely bypass RBAC and escalate their privileges.
History

Fri, 14 Feb 2025 00:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-288

Thu, 13 Feb 2025 23:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-863

Thu, 13 Feb 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 13 Feb 2025 15:45:00 +0000

Type Values Removed Values Added
Description Systems running the Instaclustr fork of Stratio's Cassandra-Lucene-Index plugin versions 4.0-rc1-1.0.0 through 4.0.16-1.0.0 and 4.1.2-1.0.0 through 4.1.8-1.0.0, installed into Apache Cassandra version 4.x, are susceptible to a vulnerability which when successfully exploited could allow authenticated Cassandra users to remotely bypass RBAC and escalate their privileges.
Title Cassandra-Lucene-Index allows bypass of Cassandra RBAC
Weaknesses CWE-288
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: netapp

Published: 2025-02-13T15:44:06.315Z

Updated: 2025-02-13T23:33:06.482Z

Reserved: 2025-02-11T21:58:04.395Z

Link: CVE-2025-26511

cve-icon Vulnrichment

Updated: 2025-02-13T16:02:47.832Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-02-13T16:16:50.270

Modified: 2025-02-14T00:15:07.667

Link: CVE-2025-26511

cve-icon Redhat

No data.