Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Sep 27, 2023

High
CISA KEV

CVE-2023-33246

ApacheRocketMQ

Several components of Apache RocketMQ, including NameServer, Broker, and Controller, are exposed to the extranet and lack permission verification. An attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as or achieve the same effect by forging the RocketMQ protocol content.

Required Action

https://lists.apache.org/thread/1s8j2c8kogthtpv3060yddk03zq0pxyp; https://nvd.nist.gov/vuln/detail/CVE-2023-33246

Vulnerability Overview

Severity
High
CISA KEV
Yes
Ransomware
Unknown
Published
Sep 6, 2023
KEV Added
Sep 6, 2023
Due Date
Sep 27, 2023
Related Articles
0

Vendor

Apache

RocketMQ