CISA KEV · Known exploitedCritical

CVE-2023-33246

Apache RocketMQ

For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution. Several components of RocketMQ, including NameServer, Broker, and Controller, are leaked on the extranet and lack permission verification, an attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as. Additionally, an attacker can achieve the same effect by forging the RocketMQ protocol content. To prevent these attacks, users are recommended to upgrade to version 5.1.1 or above for using Ro...

CVSS
9.8
EPSS
96.6%
99.9% percentile
CISA KEV
Listed
Published
2023.05.25
PRIORITY ASSESSMENT

Immediate review

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.

Known exploitationConfirmed by CISA KEV
Exploit probability96.6%
Technical severityCVSS 9.8

Vulnerability overview

For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution. Several components of RocketMQ, including NameServer, Broker, and Controller, are leaked on the extranet and lack permission verification, an attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as. Additionally, an attacker can achieve the same effect by forging the RocketMQ protocol content. To prevent these attacks, users are recommended to upgrade to version 5.1.1 or above for using Ro...

Affected product and versions

Product
Apache RocketMQ
Affected versions
< 4.9.6, >= 5.0.0 < 5.1.1
Fixed versions
4.9.6, 5.1.1

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
CISA required action

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Due date: 2023.09.27
  1. 1
    Identify

    Confirm that Apache RocketMQ and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-94
KEV added
2023.09.06
Ransomware use
미확인
CVE-2023-33246 — Apache RocketMQ | SECUFOCUS NOW