Uploaded image for project: 'Cassandra'
  1. Cassandra
  2. CASSANDRA-18550

Improve nodetool enable{audit,fullquery}log, CVE-2023-30601

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Resolved
    • Normal
    • Resolution: Fixed
    • 4.0.10, 4.1.2
    • Local/Other
    • None

    Description

      The --archive-command parameter to

      nodetool enable{audit,fullquery}log

      allows an attacker to execute arbitrary commands as the user running cassandra.

      Patch adds a configuration option which disallows using this parameter - for any existing users of --archive-command this can be re-enabled

      Attachments

        Activity

          People

            marcuse Marcus Eriksson
            marcuse Marcus Eriksson
            Marcus Eriksson
            Dinesh Joshi, Michael Semb Wever
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: