CVE-2023-30601
published 2023-05-30CVE-2023-30601: Privilege escalation when enabling FQL/Audit logs allows user with JMX access to run arbitrary commands as the user running Apache Cassandra This issue affects…
PriorityP343high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.34%
26.7th percentile
Privilege escalation when enabling FQL/Audit logs allows user with JMX access to run arbitrary commands as the user running Apache Cassandra
This issue affects Apache Cassandra: from 4.0.0 through 4.0.9, from 4.1.0 through 4.1.1.
WORKAROUND
The vulnerability requires nodetool/JMX access to be exploitable, disable access for any non-trusted users.
MITIGATION
Upgrade to 4.0.10 or 4.1.2 and leave the new FQL/Auditlog configuration property allow_nodetool_archive_command as false.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | cassandra | >= 4.0.0 < 4.0.10 | 4.0.10 |
| apache | cassandra | >= 4.1.0 < 4.1.2 | 4.1.2 |
| apache_software_foundation | apache_cassandra | 4.0.0 – 4.0.9 | — |
| apache_software_foundation | apache_cassandra | 4.1.0 – 4.1.1 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache Cassandra: Privilege escalation when enabling FQL/Audit logs
osv·2023-07-06
CVE-2023-30601 [HIGH] Apache Cassandra: Privilege escalation when enabling FQL/Audit logs
Apache Cassandra: Privilege escalation when enabling FQL/Audit logs
Privilege escalation when enabling FQL/Audit logs allows user with JMX access to run arbitrary commands as the user running Apache Cassandra
This issue affects Apache Cassandra: from 4.0.0 through 4.0.9, from 4.1.0 through 4.1.1.
WORKAROUND
The vulnerability requires nodetool/JMX access to be exploitable, disable access for any non-trusted users.
MITIGATION
Upgrade to 4.0.10 or 4.1.2 and leave the new FQL/Auditlog configuration property allow_nodetool_archive_command as false.
GHSA
Apache Cassandra: Privilege escalation when enabling FQL/Audit logs
ghsa·2023-07-06
CVE-2023-30601 [HIGH] CWE-269 Apache Cassandra: Privilege escalation when enabling FQL/Audit logs
Apache Cassandra: Privilege escalation when enabling FQL/Audit logs
Privilege escalation when enabling FQL/Audit logs allows user with JMX access to run arbitrary commands as the user running Apache Cassandra
This issue affects Apache Cassandra: from 4.0.0 through 4.0.9, from 4.1.0 through 4.1.1.
WORKAROUND
The vulnerability requires nodetool/JMX access to be exploitable, disable access for any non-trusted users.
MITIGATION
Upgrade to 4.0.10 or 4.1.2 and leave the new FQL/Auditlog configuration property allow_nodetool_archive_command as false.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-05-30
Published