CVE-2023-33246 Details
Description
For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution. Several components of RocketMQ, including NameServer, Broker, and Controller, are leaked on the extranet and lack permission verification, an attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as. Additionally, an attacker can achieve the same effect by forging the RocketMQ protocol content. To prevent these attacks, users are recommended to upgrade to version 5.1.1 or above for using RocketMQ 5.x or 4.9.6 or above for using RocketMQ 4.x .
A remote code execution vulnerability exists in Apache RocketMQ versions 5.1.0 and prior, as well as in versions through 4.9.5. This vulnerability arises from several components, including NameServer, Broker, and Controller, being exposed to the extranet without proper permission verification. Attackers can exploit this flaw by using the update configuration function to execute commands as the system user under which RocketMQ is running. Additionally, the vulnerability can be exploited by forging content that adheres to the RocketMQ protocol.
Users are advised to upgrade to Apache RocketMQ versions 5.1.1 or 4.9.6 and above. For RocketMQ 5.x, upgrade to version 5.1.2 or above. Consult the Apache RocketMQ Security Advisory for more details.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 29, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Apache RocketMQ Command Execution Vulnerability | Sep 6, 2023 | Sep 27, 2023 | Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache rocketmq | < 4.9.6 >= 5.0.0, < 5.1.1 |
CPE
Remediation
| |
Change History
16 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Oct 23, 2025 | Modified Analysis | [email protected] |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Mar 7, 2025 | Modified Analysis | [email protected] |
| Feb 13, 2025 | CVE Modified | [email protected] |
| Jan 29, 2025 | CVE Modified | CISA-ADP |
| Jan 23, 2025 | Modified Analysis | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| Jun 27, 2024 | Modified Analysis | [email protected] |
| May 14, 2024 | CVE Modified | [email protected] |
| Jul 12, 2023 | CVE Modified | [email protected] |
| Jul 7, 2023 | CVE Modified | [email protected] |
| May 31, 2023 | Initial Analysis | [email protected] |