Skip to content

[GHSA-5c4f-pxmx-xcm4] Apache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actions#7213

Closed
decsecre583 wants to merge 1 commit intogithub:decsecre583/advisory-improvement-7213from
decsecre583:patch-4
Closed

[GHSA-5c4f-pxmx-xcm4] Apache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actions#7213
decsecre583 wants to merge 1 commit intogithub:decsecre583/advisory-improvement-7213from
decsecre583:patch-4

Conversation

@decsecre583
Copy link

Updates

  • references

Comments

@github-actions github-actions bot changed the base branch from main to decsecre583/advisory-improvement-7213 March 22, 2026 18:54
@helixplant
Copy link

Hi,
The referenced patch commit apache/cassandra@066c489d764d links to https://issues.apache.org/jira/browse/CASSANDRA-20090 and is explicitly associated with CVE-2025-23015. GHSA-5c4f-pxmx-xcm4 is associated with CVE-2025-26467.

@helixplant helixplant closed this Mar 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants