CVE-2024-13733
Mar, 04/02/2025 – 10:15
CVE-2024-13733
CVE-2024-13733
Mar, 04/02/2025 – 10:15
CVE-2024-13733
CVE-2024-13529
Mar, 04/02/2025 – 10:15
CVE-2024-13529
CVE-2024-13510
Mar, 04/02/2025 – 10:15
CVE-2024-13510
CVE-2025-23015
Mar, 04/02/2025 – 10:15
CVE-2025-23015
This issue affects Apache Cassandra through 3.0.30, 3.11.17, 4.0.15, 4.1.7, 5.0.2.
Users are recommended to upgrade to versions 3.0.31, 3.11.18, 4.0.16, 4.1.8, 5.0.3, which fixes the issue.
CVE-2025-0890
Mar, 04/02/2025 – 11:15
CVE-2025-0890
CVE-2024-27137
Mar, 04/02/2025 – 11:15
CVE-2024-27137
This is same vulnerability that CVE-2020-13946 was issued for, but the Java option was changed in JDK10.
This issue affects Apache Cassandra from 4.0.2 through 5.0.2 running Java 11.
Operators are recommended to upgrade to a release equal to or later than 4.0.15, 4.1.8, or 5.0.3 which fixes the issue.
CVE-2025-24860
Mar, 04/02/2025 – 11:15
CVE-2025-24860
Users with restricted data center access can update their own permissions via data control language (DCL) statements on affected versions.
This issue affects Apache Cassandra: from 4.0.0 through 4.0.15 and from 4.1.0 through 4.1.7 for CassandraNetworkAuthorizer, and from 5.0.0 through 5.0.2 for both CassandraNetworkAuthorizer and CassandraCIDRAuthorizer.
Operators using CassandraNetworkAuthorizer or CassandraCIDRAuthorizer on affected versions should review data access rules for potential breaches. Users are recommended to upgrade to versions 4.0.16, 4.1.8, 5.0.3, which fixes the issue.
CVE-2025-20902
Mar, 04/02/2025 – 08:15
CVE-2025-20902
CVE-2025-20901
Mar, 04/02/2025 – 08:15
CVE-2025-20901
CVE-2025-20900
Mar, 04/02/2025 – 08:15
CVE-2025-20900