Details
-
Improvement
-
Status: Resolved
-
Normal
-
Resolution: Fixed
-
None
-
Operability
-
Low Hanging Fruit
-
All
-
None
-
Description
The --archive-command parameter to
nodetool enable{audit,fullquery}log
allows an attacker to execute arbitrary commands as the user running cassandra.
Patch adds a configuration option which disallows using this parameter - for any existing users of --archive-command this can be re-enabled