CVE-2023-33246
Last modified
CVE-2023-33246 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution. Several components of RocketMQ, including NameServer, Broker, and Controller, are leaked on the extranet and lack permission verification, an attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as. Additionally, an attacker can achieve the same effect by forging the RocketMQ protocol content. To prevent these attacks, users are recommended to upgrade to version 5.1.1 or above for using RocketMQ 5.x or 4.9.6 or above for using RocketMQ 4.x .. CISA has confirmed active exploitation in the wild. EPSS estimates a 96.60% chance of exploitation in the next 30 days.
Description
For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution. Several components of RocketMQ, including NameServer, Broker, and Controller, are leaked on the extranet and lack permission verification, an attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as. Additionally, an attacker can achieve the same effect by forging the RocketMQ protocol content. To prevent these attacks, users are recommended to upgrade to version 5.1.1 or above for using RocketMQ 5.x or 4.9.6 or above for using RocketMQ 4.x .
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Rocketmq | < 4.9.6 |
| Apache | Rocketmq | >= 5.0.0, < 5.1.1 |
References
- http://packetstormsecurity.com/files/173339/Apache-RocketMQ-5.1.0-Arbitrary-Code-Injection.htmlExploit, Third Party Advisory, VDB Entry
- http://www.openwall.com/lists/oss-security/2023/07/12/1Mailing List, Third Party Advisory
- https://lists.apache.org/thread/1s8j2c8kogthtpv3060yddk03zq0pxypMailing List, Vendor Advisory
- http://packetstormsecurity.com/files/173339/Apache-RocketMQ-5.1.0-Arbitrary-Code-Injection.htmlExploit, Third Party Advisory, VDB Entry
- http://www.openwall.com/lists/oss-security/2023/07/12/1Mailing List, Third Party Advisory
- https://lists.apache.org/thread/1s8j2c8kogthtpv3060yddk03zq0pxypMailing List, Vendor Advisory
- https://www.vicarius.io/vsociety/posts/rocketmq-rce-cve-2023-33246-33247Exploit, Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-33246Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2023-33246?
How severe is CVE-2023-33246?
How do I fix CVE-2023-33246?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-33240Foxit PDF Reader (12.1.1.15289 and earlier) and Foxit PDF Ed…7.8
- CVE-2023-33241Crypto wallets implementing the GG18 or GG20 TSS protocol mi…9.1
- CVE-2023-33242Crypto wallets implementing the Lindell17 TSS protocol might…8.1
- CVE-2023-33243RedTeam Pentesting discovered that the web interface of STAR…8.1
- CVE-2023-33244Obsidian before 1.2.2 allows calls to unintended APIs (for m…8.2
- CVE-2023-33245Minecraft through 1.19 and 1.20 pre-releases before 7 (Java)…8.8
- CVE-2023-33247Talend Data Catalog remote harvesting server before 8.0-2023…7.5
- CVE-2023-33248Amazon Alexa software version 8960323972 on Echo Dot 2nd gen…7.6
- CVE-2023-3325The CMS Commander plugin for WordPress is vulnerable to auth…9.8
- CVE-2023-33250The Linux kernel 6.3 has a use-after-free in iopt_unmap_iova…4.4
- CVE-2023-33251When Akka HTTP before 10.5.2 accepts file uploads via the Fi…5.5
- CVE-2023-33252iden3 snarkjs through 0.6.11 allows double spending because …7.5
Are you affected by CVE-2023-33246?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
