Apache Cassandra: Privilege escalation when enabling FQL/Audit logs
High severity
GitHub Reviewed
Published
Jul 6, 2023
to the GitHub Advisory Database
•
Updated Feb 23, 2024
Package
Affected versions
>= 4.1.0, < 4.1.2
>= 4.0.0, < 4.0.10
Patched versions
4.1.2
4.0.10
Description
Published by the National Vulnerability Database
May 30, 2023
Published to the GitHub Advisory Database
Jul 6, 2023
Reviewed
Jul 6, 2023
Last updated
Feb 23, 2024
Privilege escalation when enabling FQL/Audit logs allows user with JMX access to run arbitrary commands as the user running Apache Cassandra
This issue affects Apache Cassandra: from 4.0.0 through 4.0.9, from 4.1.0 through 4.1.1.
WORKAROUND
The vulnerability requires nodetool/JMX access to be exploitable, disable access for any non-trusted users.
MITIGATION
Upgrade to 4.0.10 or 4.1.2 and leave the new FQL/Auditlog configuration property allow_nodetool_archive_command as false.
References