GHSA-x3cq-8f32-5f63

    Dashboard / Vulnerabilities / GHSA-x3cq-8f32-5f63

    GHSA-x3cq-8f32-5f63

    Published: 6 Jul 2023Last Modified: 22 Oct 2025

    Summary: Apache RocketMQ may have remote code execution vulnerability when using update configuration function

    Details: For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution.  Several components of RocketMQ, including NameServer, Broker, and Controller, are leaked on the extranet and lack permission verification, an attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as. Additionally, an attacker can achieve the same effect by forging the RocketMQ protocol content.  To prevent these attacks, users are recommended to upgrade to version 5.1.1 or above for using RocketMQ 5.x or 4.9.6 or above for using RocketMQ 4.x .

    Affected packages

    Package

    Name: org.apache.rocketmq:rocketmq-broker

    Purl: pkg:maven/org.apache.rocketmq/rocketmq-broker

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 5.0.0
    Fixed -5.1.1

    Affected versions

    5.0.0
    5.0.0-PREVIEW

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-x3cq-8f32-5f63 | CVE-DB