← volver
CVE-2023-33246criticalbajo ataqueCWE-94

Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function

100Vexday Risk Score

Corrige ahora. Ella está bajo explotación confirmada por CISA y tiene exploit funcional público.

ssvc Actcvss 9.8epss 97%
de la publicación al arma6 días
Publicada en NVD24 may
1ª PoC+6d
metasploit23 may
CISA KEV+105d
probabilidad de explotación
97%top 1% de las CVE
explotación observada
CISA + VulnCheck
22 exploit(s) público(s)
Acción exigida por CISAplazo federal: 2023-09-27

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Versiones

Afectadas
maven/org.apache.rocketmq:rocketmq-broker >= 5.0.0, < 5.1.1; maven/org.apache.rocketmq:rocketmq-namesrv >= 4.0.0, < 4.9.6; maven/org.apache.rocketmq:rocketmq-controller >= 5.0.0, < 5.1.1; maven/org.apache.rocketmq:rocketmq-namesrv >= 5.0.0, < 5.1.1
Corregidas en
maven/org.apache.rocketmq:rocketmq-broker 5.1.1; maven/org.apache.rocketmq:rocketmq-namesrv 4.9.6; maven/org.apache.rocketmq:rocketmq-controller 5.1.1; maven/org.apache.rocketmq:rocketmq-namesrv 5.1.1
Investigado y redactado con IA a partir del advisory del fabricante y análisis públicos, con las fuentes citadas. Verifica siempre la versión corregida en el advisory oficial antes de actuar.
For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution.  Several components of RocketMQ, including NameServer, Broker, and Controller, are leaked on the extranet and lack permission verification, an attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as. Additionally, an attacker can achieve the same effect by forging the RocketMQ protocol content.  To prevent these attacks, users are recommended to upgrade to version 5.1.1 or above for using RocketMQ 5.x or 4.9.6 or above for using RocketMQ 4.x .
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.