CVE-2023-33972

    Dashboard / Vulnerabilities / CVE-2023-33972

    CVE-2023-33972

    Published: 27 Sept 2023Last Modified: 12 Aug 2026

    Summary: Privilege escalation from having CREATE access on a keyspace in Scylladb

    Details: Scylladb is a NoSQL data store using the seastar framework, compatible with Apache Cassandra. Authenticated users who are authorized to create tables in a keyspace can escalate their privileges to access a table in the same keyspace, even if they don't have permissions for that table. This issue has not yet been patched. A workaround to address this issue is to disable CREATE privileges on a keyspace, and create new tables on behalf of other users.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 0
    Fixed -None

    Affected versions

    scylla-5.2.8
    scylla-5.2.7
    scylla-5.2.6
    scylla-5.2.5
    scylla-5.2.4
    scylla-5.2.3
    scylla-5.2.2
    scylla-5.2.1
    scylla-5.2.0
    scylla-5.2.0-rc5
    scylla-5.2.0-rc4
    scylla-5.2.0-rc3
    scylla-5.2.0-rc2
    scylla-5.2.0-rc1
    scylla-5.2.0-rc0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2023-33972 | CVE-DB