CVE-2023-30601

Severity
7.8HIGH
EPSS
0.0%
top 94.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 30
Latest updateJul 6

Description

Privilege escalation when enabling FQL/Audit logs allows user with JMX access to run arbitrary commands as the user running Apache Cassandra This issue affects Apache Cassandra: from 4.0.0 through 4.0.9, from 4.1.0 through 4.1.1. WORKAROUND The vulnerability requires nodetool/JMX access to be exploitable, disable access for any non-trusted users. MITIGATION Upgrade to 4.0.10 or 4.1.2 and leave the new FQL/Auditlog configuration property allow_nodetool_archive_command as false.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

NVDapache/cassandra4.0.04.0.10+1
Mavenorg.apache.cassandra:cassandra-all4.1.04.1.2+1
CVEListV5apache_software_foundation/apache_cassandra4.0.04.0.9+1

🔴Vulnerability Details

3
OSV
Apache Cassandra: Privilege escalation when enabling FQL/Audit logs2023-07-06
GHSA
Apache Cassandra: Privilege escalation when enabling FQL/Audit logs2023-07-06
CVEList
Apache Cassandra: Privilege escalation when enabling FQL/Audit logs2023-05-30
CVE-2023-30601 (HIGH CVSS 7.8) | Privilege escalation when enabling | cvebase.io