← back
CVE-2023-33246criticalunder attackCWE-94

Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 9.8epss 97%
from disclosure to weapon6 days
Published on NVDMay 24
1st PoC+6d
metasploitMay 23
CISA KEV+105d
exploitation probability
97%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
22 public exploit(s)
Action required by CISAfederal deadline: 2023-09-27

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Versions

Affected
maven/org.apache.rocketmq:rocketmq-broker >= 5.0.0, < 5.1.1; maven/org.apache.rocketmq:rocketmq-namesrv >= 4.0.0, < 4.9.6; maven/org.apache.rocketmq:rocketmq-controller >= 5.0.0, < 5.1.1; maven/org.apache.rocketmq:rocketmq-namesrv >= 5.0.0, < 5.1.1
Fixed in
maven/org.apache.rocketmq:rocketmq-broker 5.1.1; maven/org.apache.rocketmq:rocketmq-namesrv 4.9.6; maven/org.apache.rocketmq:rocketmq-controller 5.1.1; maven/org.apache.rocketmq:rocketmq-namesrv 5.1.1
Researched and written with AI from the vendor advisory and public analysis, with the sources above. Always confirm the fixed version in the official advisory before acting.
For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution.  Several components of RocketMQ, including NameServer, Broker, and Controller, are leaked on the extranet and lack permission verification, an attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as. Additionally, an attacker can achieve the same effect by forging the RocketMQ protocol content.  To prevent these attacks, users are recommended to upgrade to version 5.1.1 or above for using RocketMQ 5.x or 4.9.6 or above for using RocketMQ 4.x .
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.