Privilege escalation when enabling FQL/Audit logs allows user with JMX access to run arbitrary commands as the user running Apache Cassandra This issue affects Apache Cassandra: from 4.0.0 through 4.0.9, from 4.1.0 through 4.1.1.
WORKAROUND The vulnerability requires nodetool/JMX access to be exploitable, disable access for any non-trusted users.
MITIGATION Upgrade to 4.0.10 or 4.1.2 and leave the new FQL/Auditlog configuration property allownodetoolarchive_command as false.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/30xxx/CVE-2023-30601.json",
"cna_assigner": "apache",
"unresolved_ranges": [
{
"source": "AFFECTED_FIELD",
"extracted_events": [
{
"introduced": "4.0.0"
},
{
"last_affected": "4.0.9"
},
{
"introduced": "4.1.0"
},
{
"last_affected": "4.1.1"
}
]
},
{
"source": "DESCRIPTION",
"extracted_events": [
{
"introduced": "4.0.0"
},
{
"fixed": "4.0.9"
},
{
"introduced": "4.1.0"
},
{
"fixed": "4.1.1"
}
]
}
],
"cwe_ids": [
"CWE-269"
]
}