CVE-2023-33246
Apache RocketMQ may have remote code execution vulnerability when using update configuration function
描述
For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution. Several components of RocketMQ, including NameServer, Broker, and Controller, are leaked on the extranet and lack permission verification, an attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as. Additionally, an attacker can achieve the same effect by forging the RocketMQ protocol content. To prevent these attacks, users are recommended to upgrade to version 5.1.1 or above for using RocketMQ 5.x or 4.9.6 or above for using RocketMQ 4.x .
如何修補 CVE-2023-33246
要修補 CVE-2023-33246,請將受影響套件升級到下列已修補版本。
- —升級至 5.1.1 或更新版本
- —升級至 5.1.1 或更新版本
- —升級至 4.9.6 或更新版本
CVE-2023-33246 正在被利用嗎?
是 — CVE-2023-33246 已列入 CISA Known Exploited Vulnerabilities (KEV) 清單,代表正在被實際利用,請立即修補。
受影響套件(3)
- >= 5.0.0, < 5.1.1
- >= 5.0.0, < 5.1.1
- >= 4.0.0, < 4.9.6
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H |