Sensitive Information Leak in cqlsh in Apache Cassandra 4.0 allows access to sensitive information, like passwords, from previously executed cqlsh command via ~/.cassandra/cqlsh_history local file access.
Users are recommended to upgrade to version 4.0.20, which fixes this issue.
--
Description: Cassandra's command-line tool, cqlsh, provides a command history feature that allows users to recall previously executed commands using the up/down arrow keys. These history records are saved in the ~/.cassandra/cqlsh_history file in the user's home directory.
However, cqlsh does not redact sensitive information when saving command history. This means that if a user executes operations involving passwords (such as logging in or creating users) within cqlsh, these passwords are permanently stored in cleartext in the history file on the disk.
References
| Link | Resource |
|---|---|
| https://issues.apache.org/jira/browse/CASSANDRA-21180 | Issue Tracking Patch Vendor Advisory |
| https://lists.apache.org/thread/ft77zrk2mzt8qsch4g6jqjj4901d22k3 | Mailing List Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2026/04/07/8 | Mailing List Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-04-07 17:16
Updated : 2026-06-17 10:27
NVD link : CVE-2026-27315
Mitre link : CVE-2026-27315
CVE.ORG link : CVE-2026-27315
JSON object : View
Products Affected
apache
- cassandra
CWE
CWE-532
Insertion of Sensitive Information into Log File
