Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Cassandra-Lucene-Index allows bypass of Cassandra RBAC
Vulnerability Description
Systems running the Instaclustr fork of Stratio's Cassandra-Lucene-Index plugin versions 4.0-rc1-1.0.0 through 4.0.16-1.0.0 and 4.1.2-1.0.0 through 4.1.8-1.0.0, installed into Apache Cassandra version 4.x, are susceptible to a vulnerability which when successfully exploited could allow authenticated Cassandra users to remotely bypass RBAC and escalate their privileges.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
授权机制不正确
Vulnerability Title
cassandra-lucene-index 安全漏洞
Vulnerability Description
cassandra-lucene-index是NetApp Instaclustr开源的一个基于 Lucene 的 Cassandra 二级索引。 cassandra-lucene-index存在安全漏洞。经过身份验证的攻击者利用该漏洞可以远程绕过RBAC并提升其权限。
CVSS Information
N/A
Vulnerability Type
N/A