{"id":"GHSA-m9p2-j4hg-g373","summary":"Apache Cassandra: Privilege escalation when enabling FQL/Audit logs","details":"Privilege escalation when enabling FQL/Audit logs allows user with JMX access to run arbitrary commands as the user running Apache Cassandra\nThis issue affects Apache Cassandra: from 4.0.0 through 4.0.9, from 4.1.0 through 4.1.1.\n\nWORKAROUND\nThe vulnerability requires nodetool/JMX access to be exploitable, disable access for any non-trusted users.\n\nMITIGATION\nUpgrade to 4.0.10 or 4.1.2 and leave the new FQL/Auditlog configuration property allow_nodetool_archive_command as false.","aliases":["BIT-cassandra-2023-30601","CVE-2023-30601"],"modified":"2026-08-07T08:12:20.454244364Z","published":"2023-07-06T21:15:06Z","database_specific":{"github_reviewed_at":"2023-07-06T23:50:30Z","nvd_published_at":"2023-05-30T08:15:10Z","cwe_ids":["CWE-269"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-30601"},{"type":"WEB","url":"https://github.com/apache/cassandra/commit/22d74c711658507addfd67e2c78b04a9b88413b2"},{"type":"WEB","url":"https://github.com/apache/cassandra/commit/aafb4d19448f12ce600dc4e84a5b181308825b32"},{"type":"PACKAGE","url":"https://github.com/apache/cassandra"},{"type":"WEB","url":"https://issues.apache.org/jira/browse/CASSANDRA-18550"},{"type":"WEB","url":"https://lists.apache.org/thread/f74p9jdhmmp7vtrqd8lgm8bq3dhxl8vn"}],"affected":[{"package":{"name":"org.apache.cassandra:cassandra-all","ecosystem":"Maven","purl":"pkg:maven/org.apache.cassandra/cassandra-all"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.1.0"},{"fixed":"4.1.2"}]}],"versions":["4.1.0","4.1.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-m9p2-j4hg-g373/GHSA-m9p2-j4hg-g373.json"}},{"package":{"name":"org.apache.cassandra:cassandra-all","ecosystem":"Maven","purl":"pkg:maven/org.apache.cassandra/cassandra-all"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.0.0"},{"fixed":"4.0.10"}]}],"versions":["4.0.0","4.0.1","4.0.2","4.0.3","4.0.4","4.0.5","4.0.6","4.0.7","4.0.8","4.0.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-m9p2-j4hg-g373/GHSA-m9p2-j4hg-g373.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}