Apache Cassandra: Privilege escalation when enabling FQL/Audit logs
CVE-2023-30601
7.8HIGH
Summary
A vulnerability exists in Apache Cassandra which allows an unauthorized user with JMX access to execute arbitrary commands, potentially gaining elevated privileges as the user running Apache Cassandra. This risks the security of the application by enabling execution of unintended commands. To mitigate this risk, it is recommended to upgrade to version 4.0.10 or 4.1.2, and ensure that the 'allow_nodetool_archive_command' setting in the FQL/Audit log configuration is disabled. Additionally, limiting nodetool/JMX access to trusted users is essential to prevent exploitation.
Affected Version(s)
Apache Cassandra 4.0.0 <= 4.0.9
Apache Cassandra 4.1.0 <= 4.1.1
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Gal Elbaz at Oligo