GHSA-gpq8-963w-8qc9

    Dashboard / Vulnerabilities / GHSA-gpq8-963w-8qc9

    GHSA-gpq8-963w-8qc9

    Published: 12 Jul 2023Last Modified: 13 Feb 2025

    Summary: RocketMQ NameServer component Code Injection vulnerability

    Details: The RocketMQ NameServer component still has a remote command execution vulnerability as the CVE-2023-33246 issue was not completely fixed in version 5.1.1. When NameServer address are leaked on the extranet and lack permission verification, an attacker can exploit this vulnerability by using the update configuration function on the NameServer component to execute commands as the system users that RocketMQ is running as. It is recommended for users to upgrade their NameServer version to 5.1.2 or above for RocketMQ 5.x or 4.9.7 or above for RocketMQ 4.x to prevent these attacks.

    Affected packages

    Package

    Name: org.apache.rocketmq:rocketmq-namesrv

    Purl: pkg:maven/org.apache.rocketmq/rocketmq-namesrv

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -4.9.7

    Affected versions

    4.0.0-incubating

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-gpq8-963w-8qc9 | CVE-DB