CVE-2019-17572
Directory traversal in Apache RocketMQ
EPSS 3.0%
描述
In Apache RocketMQ 4.2.0 to 4.6.0, when the automatic topic creation in the broker is turned on by default, an evil topic like “../../../../topic2020” is sent from rocketmq-client to the broker, a topic folder will be created in the parent directory in brokers, which leads to a directory traversal vulnerability. Users of the affected versions should apply one of the following: Upgrade to Apache RocketMQ 4.6.1 or later.
如何修補 CVE-2019-17572
要修補 CVE-2019-17572,請將受影響套件升級到下列已修補版本。
- Maven/org.apache.rocketmq:rocketmq-broker—升級至 4.6.1 或更新版本
CVE-2019-17572 正在被利用嗎?
低 — EPSS 為 3.0%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- >= 4.2.0, < 4.6.1