Junglewise Threat Intelligence

CVE-2023-33246: Apache RocketMQ may have remote code execution vulnerability when using update configuration function

CVE-2023-33246 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2023-07-06

Vendors: Apache.

Executive brief

Apache RocketMQ components (NameServer, Broker, and Controller) lack proper permission verification when exposed to the network. Attackers can exploit the update configuration function or forge protocol content to execute arbitrary commands as the system user running RocketMQ.

Affected products

  • Apache RocketMQ <= 5.1.0, <= 4.9.5

Timeline

  • 2023-09-06: disclosed
  • 2023-09-06: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-07-12: other: Mailing list disclosure