Security
Loading…

CVE-2023-33246

UNKNOWNKnown Exploited
Description

Several components of Apache RocketMQ, including NameServer, Broker, and Controller, are exposed to the extranet and lack permission verification. An attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as or achieve the same effect by forging the RocketMQ protocol content.

Timeline
Published:September 6th, 2023 12:00 AM
Last modified:September 6th, 2023 12:00 AM
Added to KEV:September 6th, 2023
CVSS Scoring

No CVSS v3 score available

Affected Software
From NVD CPE configuration data

Vendors

Apache

Products

RocketMQ
Weaknesses (CWE)
References & Reports
Advisories, patches, and third-party reports

No references available.

Source: CISA KEV + NVD · Data may lag official sources by up to one minute