CNNVD-202508-2998 Information

CNNVD ID

CNNVD-202508-2998

CVE-2025-26467

  • CNNVD Published: 2025-08-25

Description (Chinese)

Apache Cassandra是美国阿帕奇(Apache)基金会的一个分布式Nosql数据库。 Apache Cassandra 3.0.30版本、3.11.17版本、4.0.16版本、4.1.7版本和5.0.2版本存在安全漏洞,该漏洞源于权限定义不当,可能导致权限提升。

Description (English)

Apache Cassandra is a distributed Nosql database of the Apache Foundation in the United States. There is a security loophole in Appache Cassandra, 3.030, 3.11.7, 4.0.16, 4.1.7 and 5.0.2, which stems from an inappropriate definition of authority, which may lead to an increase in authority.

Hazard Level

Medium

Vulnerability Type

其他

Affected Vendor

阿帕奇

Published

2025-08-25

Last Modified

2026-02-24

References

https://lists.apache.org/thread/xxj36rr4d6mzyqpld05dn8b9951hfpz7 https://nvd.nist.gov/vuln/detail/CVE-2025-26467

Patch

https://lists.apache.org/thread/xxj36rr4d6mzyqpld05dn8b9951hfpz7

Share on: