Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100Vexday Risk Score
Corrige ahora. Ella está bajo explotación confirmada por CISA y tiene exploit funcional público.
ssvc Actcvss 9.8epss 97%
de la publicación al arma6 días
Publicada en NVD24 may
1ª PoC+6d
metasploit23 may
CISA KEV+105d
probabilidad de explotación
97%top 1% de las CVE
explotación observada
síCISA + VulnCheck
22 exploit(s) público(s)
Acción exigida por CISAplazo federal: 2023-09-27
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Versiones
Afectadas
maven/org.apache.rocketmq:rocketmq-broker >= 5.0.0, < 5.1.1; maven/org.apache.rocketmq:rocketmq-namesrv >= 4.0.0, < 4.9.6; maven/org.apache.rocketmq:rocketmq-controller >= 5.0.0, < 5.1.1; maven/org.apache.rocketmq:rocketmq-namesrv >= 5.0.0, < 5.1.1
Corregidas en
maven/org.apache.rocketmq:rocketmq-broker 5.1.1; maven/org.apache.rocketmq:rocketmq-namesrv 4.9.6; maven/org.apache.rocketmq:rocketmq-controller 5.1.1; maven/org.apache.rocketmq:rocketmq-namesrv 5.1.1
Investigado y redactado con IA a partir del advisory del fabricante y análisis públicos, con las fuentes citadas. Verifica siempre la versión corregida en el advisory oficial antes de actuar.
For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution.
Several components of RocketMQ, including NameServer, Broker, and Controller, are leaked on the extranet and lack permission verification, an attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as. Additionally, an attacker can achieve the same effect by forging the RocketMQ protocol content.
To prevent these attacks, users are recommended to upgrade to version 5.1.1 or above for using RocketMQ 5.x or 4.9.6 or above for using RocketMQ 4.x .
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Productos afectados
Apache Software Foundation · Apache RocketMQPoCs públicas encontradas — 22
githubgithub.com/SuperZero/CVE-2023-33246★ 114cve_referencegithub.com/Malayke/CVE-2023-33246_RocketMQ_RCE_EXPLOIT★ 104githubgithub.com/Le1a/CVE-2023-33246★ 81githubgithub.com/I5N0rth/CVE-2023-33246★ 62githubgithub.com/vulncheck-oss/fetch-broker-conf★ 5githubgithub.com/P4x1s/CVE-2023-33246★ 3githubgithub.com/4mazing/CVE-2023-33246-Copy★ 2githubgithub.com/0xKayala/CVE-2023-33246★ 2githubgithub.com/PavilionQ/CVE-2023-33246-mitigation★ 1githubgithub.com/d0rb/CVE-2023-33246★ 1githubgithub.com/MkJos/CVE-2023-33246_RocketMQ_RCE_EXP★ 1githubgithub.com/Sumitpathania03/Apache-RocketMQ-CVE-2023-33246-★ 0githubgithub.com/shoucheng3/apache__rocketmq_CVE-2023-33246_5-1-0★ 0vulncheckvulncheck.com/xdb/de034939c964no verificadocve_referencegithub.com/jakabakos/CVE-2023-33246_Apache_RocketMQ_RCEno verificadovulncheckvulncheck.com/xdb/893a13b107deno verificadovulncheckvulncheck.com/xdb/cf4f1e593dfcno verificadovulncheckvulncheck.com/xdb/b486dcf3f31dno verificadovulncheckvulncheck.com/xdb/3068e2f9ef10no verificadovulncheckvulncheck.com/xdb/6a010bfe0097no verificadovulncheckvulncheck.com/xdb/d4697400457fno verificadocve_referencepacketstormsecurity.com/files/173339/Apache-RocketMQ-5.1.0-Arbitrary-Code-Injection.htmlno verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
Referencias
http://packetstormsecurity.com/files/173339/Apache-RocketMQ-5.1.0-Arbitrary-Code-Injection.htmlhttps://github.com/jakabakos/CVE-2023-33246_Apache_RocketMQ_RCEhttps://github.com/Malayke/CVE-2023-33246_RocketMQ_RCE_EXPLOIThttps://lists.apache.org/thread/1s8j2c8kogthtpv3060yddk03zq0pxyphttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-33246https://www.vicarius.io/vsociety/posts/rocketmq-rce-cve-2023-33246-33247http://www.openwall.com/lists/oss-security/2023/07/12/1