PT-2024-5329 · Apache · Rocketmq
Baochengzhang
·
Published
2024-01-15
·
Updated
2024-09-10
·
CVE-2024-23321
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
RocketMQ versions 5.2.0 and below
Description
The issue is related to insufficient protection of service data in the RocketMQ messaging platform. This could allow a remote attacker to gain unauthorized access to protected information. Under certain conditions, even with authentication and authorization functions enabled, there is a risk of exposing sensitive information to an unauthorized actor. An attacker with regular user privileges or listed in the IP whitelist could potentially acquire the administrator's account and password through specific interfaces, granting them full control over RocketMQ if they have access to the broker IP address list.
Recommendations
For RocketMQ versions 5.2.0 and below, upgrade to version 5.3.0 or newer to mitigate the security threats. When upgrading to version Apache RocketMQ 5.3.0, use RocketMQ ACL 2.0 instead of the original RocketMQ ACL.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rocketmq