Skip to content

Conversation

@maximthomas
Copy link
Contributor

CVE-2025-23015 Apache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actions
CVE-2024-27137 Apache Cassandra: unrestricted deserialization of JMX authentication credentials
CVE-2025-24860 Apache Cassandra: CassandraNetworkAuthorizer and CassandraCIDRAuthorizer can be bypassed allowing access to different network regions

@maximthomas maximthomas requested a review from vharseko December 9, 2025 14:52
@maximthomas maximthomas merged commit 2c95c15 into OpenIdentityPlatform:master Dec 10, 2025
12 checks passed
@maximthomas maximthomas deleted the issues/cassandra-cves branch December 10, 2025 06:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants