Apache Rocketmq Broker - Unauthenticated Access
Apache Rocketmq Unauthenticated Access were detected.
共找到 3 条公开漏洞记录
Apache Rocketmq Unauthenticated Access were detected.
Apache RocketMQ是一款低延迟、高并发、高可用、高可靠的分布式消息中间件。CVE-2023-37582 中,由于对 CVE-2023-33246 修复不完善,导致在Apache RocketMQ NameServer 存在未授权访问的情况下,攻击者可构造恶意请求以RocketMQ运行的系统用户身份执行命令。 影响版本: Apache RocketMQ NameServer 5.0.0 ~ 5.1.1 Apache RocketMQ NameServer 4.0.0 ~ 4.9.6 安全版本: Apache RocketMQ NameServer 5.1.2 Apache RocketMQ NameServer 4.9.7
For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution. Several components of RocketMQ, including NameServer, Broker, and Controller, are leaked on the extranet and lack permission verification, an attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as. Additionally, an attacker can achieve the same effect by forging the RocketMQ protocol content. To prevent these attacks, users are recommended to upgrade to version 5.1.1 or above for using RocketMQ 5.x or 4.9.6 or above for using RocketMQ 4.x .