Questions on CEP-21

2025-02-11 Thread Long Pan
Hey Sam, *The improvements in CEP-21 look awesome.* I am currently running Cassandra 4.1 and plan to upgrade to 5.x in the future, where CEP-21 has been implemented. I have a few questions: 1.

CVE-2025-26467: Apache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actions (4.0.16 only)

2025-02-11 Thread Paulo Motta
Severity: moderate Affected versions: - Apache Cassandra 4.0.16 Description: Privilege Defined With Unsafe Actions vulnerability in Apache Cassandra. An user with MODIFY permission ON ALL KEYSPACES can escalate privileges to superuser within a targeted Cassandra cluster via unsafe actions to