BIT-scylladb-2023-33972

    Dashboard / Vulnerabilities / BIT-scylladb-2023-33972

    BIT-scylladb-2023-33972

    Published: 14 May 2024Last Modified: 8 Sept 2026

    Summary: Privilege escalation from having CREATE access on a keyspace in Scylladb

    Details: Scylladb is a NoSQL data store using the seastar framework, compatible with Apache Cassandra. Authenticated users who are authorized to create tables in a keyspace can escalate their privileges to access a table in the same keyspace, even if they don't have permissions for that table. This issue has not yet been patched. A workaround to address this issue is to disable CREATE privileges on a keyspace, and create new tables on behalf of other users.

    Affected packages

    Package

    Name: scylladb

    Purl: pkg:bitnami/scylladb

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -5.2.9

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    BIT-scylladb-2023-33972 | CVE-DB