-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from the lack of a security check in StorageService.enableFullQueryLogger() when processing archive commands. The patch introduced a check for 'allow_nodetool_archive_command' to prevent unauthorized command execution. The test modifications and commit diff confirm this function was the entry point for the insecure operation. The function's direct handling of user-provided archive_command parameters (via JMX/nodetool) makes it the clear vulnerability source when the configuration flag is improperly set.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.apache.cassandra:cassandra-all | maven | >= 4.1.0, < 4.1.2 | 4.1.2 |
| org.apache.cassandra:cassandra-all | maven | >= 4.0.0, < 4.0.10 | 4.0.10 |
Ongoing coverage of React2Shell