https://seclists.org/oss-sec/2023/q2/201: CVE-2023-30601: Apache Cassandra: Privilege escalation when enabling FQL/Audit logs
Published May 29, 2023
·Updated
Affected Software
1 affected component
Apache Cassandra>=4.0.0<=4.0.9, >=4.1.0<=4.1.1
Frequently Asked Questions
1
What is the severity of CVE-2023-30601?
The severity of CVE-2023-30601 is classified as important.
2
Which versions of Apache Cassandra are affected by CVE-2023-30601?
Apache Cassandra versions 4.0.0 through 4.0.9 and 4.1.0 through 4.1.1 are affected by CVE-2023-30601.
3
How does CVE-2023-30601 exploit privilege escalation?
CVE-2023-30601 allows a user with JMX access to run arbitrary commands as the user running Apache Cassandra when enabling FQL/Audit logs.
4
How do I fix CVE-2023-30601?
To fix CVE-2023-30601, upgrade to a non-vulnerable version of Apache Cassandra that addresses this privilege escalation issue.
5
What are the risks of not addressing CVE-2023-30601?
Failing to address CVE-2023-30601 can lead to unauthorized privilege escalation and potential compromise of the Apache Cassandra instance.