Executive brief
Apache RocketMQ components (NameServer, Broker, and Controller) lack proper permission verification when exposed to the network. Attackers can exploit the update configuration function or forge protocol content to execute arbitrary commands as the system user running RocketMQ.
Affected products
- Apache RocketMQ <= 5.1.0, <= 4.9.5
Timeline
- 2023-09-06: disclosed
- 2023-09-06: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-07-12: other: Mailing list disclosure