CVE-2023-30601
HIGHApache Cassandra 4.0.0-4.0.9 and 4.1.0-4.1.1 - Privilege Escalation via FQL/Audit Log Configuration
Title source: llmDescription
Privilege escalation when enabling FQL/Audit logs allows user with JMX access to run arbitrary commands as the user running Apache Cassandra This issue affects Apache Cassandra: from 4.0.0 through 4.0.9, from 4.1.0 through 4.1.1. WORKAROUND The vulnerability requires nodetool/JMX access to be exploitable, disable access for any non-trusted users. MITIGATION Upgrade to 4.0.10 or 4.1.2 and leave the new FQL/Auditlog configuration property allow_nodetool_archive_command as false.
References (1)
Core 1
Core References
Mailing List vendor-advisory
https://lists.apache.org/thread/f74p9jdhmmp7vtrqd8lgm8bq3dhxl8vn
Scores
CVSS v3
7.8
EPSS
0.0002
EPSS Percentile
6.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-269
Status
published
Products (2)
apache/cassandra
4.0.0 - 4.0.10
org.apache.cassandra/cassandra-all
4.1.0 - 4.1.2Maven
Published
May 30, 2023
Tracked Since
Feb 18, 2026