{"id":"BIT-cassandra-2023-30601","summary":"Apache Cassandra: Privilege escalation when enabling FQL/Audit logs","details":"Privilege escalation when enabling FQL/Audit logs allows user with JMX access to run arbitrary commands as the user running Apache Cassandra\nThis issue affects Apache Cassandra: from 4.0.0 through 4.0.9, from 4.1.0 through 4.1.1.\n\nWORKAROUND\nThe vulnerability requires nodetool/JMX access to be exploitable, disable access for any non-trusted users.\n\nMITIGATION\nUpgrade to 4.0.10 or 4.1.2 and leave the new FQL/Auditlog configuration property allow_nodetool_archive_command as false.","aliases":["CVE-2023-30601","GHSA-m9p2-j4hg-g373"],"modified":"2026-09-08T08:45:39.326203800Z","published":"2024-03-06T10:50:45.472Z","database_specific":{"severity":"High","cpes":["cpe:2.3:a:apache:cassandra:*:*:*:*:*:*:*:*"]},"references":[{"type":"DISCUSSION","url":"https://lists.apache.org/thread/f74p9jdhmmp7vtrqd8lgm8bq3dhxl8vn"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-30601"}],"affected":[{"package":{"name":"cassandra","ecosystem":"Bitnami","purl":"pkg:bitnami/cassandra"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.0.0"},{"fixed":"4.0.10"},{"introduced":"4.1.0"},{"fixed":"4.1.2"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/cassandra/BIT-cassandra-2023-30601.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}],"schema_version":"1.9.0"}