Multiple Apple Products Vulnerabilities
February 11, 2025Apple Releases Emergency Update to Patch Actively Exploited iOS Zero-Day CVE-2025-24200
February 11, 2025Multiple Apple Products Vulnerabilities
February 11, 2025Apple Releases Emergency Update to Patch Actively Exploited iOS Zero-Day CVE-2025-24200
February 11, 2025Severity
High
Analysis Summary
CVE-2025-24860 CVSS:8.1
Incorrect Authorization vulnerability in Apache Cassandra allowing users to access a datacenter or IP/CIDR groups they should not be able to when using CassandraNetworkAuthorizer or CassandraCIDRAuthorizer. Users with restricted data center access can update their own permissions via data control language (DCL) statements on affected versions. This issue affects Apache Cassandra: from 4.0.0 through 4.0.15 and from 4.1.0 through 4.1.7 for CassandraNetworkAuthorizer, and from 5.0.0 through 5.
CVE-2024-27137 CVSS:7.7
Apache Cassandra is vulnerable to a man-in-the-middle attack, caused by an unrestricted deserialization of JMX authentication credentials.
CVE-2025-23015 CVSS:8.8
Apache Cassandra could allow a remote authenticated attacker to gain elevated privileges on the system, caused by a privilege defined with unsafe actions flaw.
CVE-2024-37358 CVSS:7.5
Apache James is vulnerable to a denial of service, caused by the use of IMAP literals.
CVE-2024-45626 CVSS:7.5
Apache James is vulnerable to a denial of service, caused by an unbounded memory consumption flaw in the JMAP HTML to text plain implementation.
Impact
- Security Bypass
- Denial of Service
- Gain Access
- Privilege Escalation
Indicators of Compromise
CVE
CVE-2025-24860
CVE-2024-27137
CVE-2025-23015
CVE-2024-37358
CVE-2024-45626
Affected Vendors
Affected Products
- Apache Cassandra - 4.0.0
- Apache Cassandra - 4.0.15
- Apache Cassandra - 4.1.0
- Apache Cassandra - 4.1.7
- Apache Cassandra - 4.0.2
- Apache Cassandra - 4.0.14
- Apache Cassandra - 3.0.0
- Apache Cassandra - 3.0.30
- Apache Cassandra - 3.1.0
- Apache James - 3.7.5
- Apache James - 3.8.0
Remediation
Upgrade to the latest version of Apache Products, available from the Apache Website.