KEVIntel
9.8
CVSS
Critical

CVE-2023-33246

PUBLISHED

Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function

Exploited in the wild Remote Low complexity No user interaction
Vendor
Apache Software Foundation
Product
Apache RocketMQ
Published
May 24, 2023
EPSS

Description

For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution.  Several components of RocketMQ, including NameServer, Broker, and Controller, are leaked on the extranet and lack permission verification, an attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as. Additionally, an attacker can achieve the same effect by forging the RocketMQ protocol content.  To prevent these attacks, users are recommended to upgrade to version 5.1.1 or above for using RocketMQ 5.x or 4.9.6 or above for using RocketMQ 4.x .

apache cisa nuclei_scanner metasploit

CVSS scores

CVSS v3.1 9.8 Critical

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploitation status

Exploited in the wild

Recorded 2023-09-06 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
Yes
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Sep 06, 2023

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

apache_rocketmq_update_config

metasploit · Created Unknown

Metasploit module for CVE-2023-33246

0xKayala/CVE-2023-33246

github · Created 2023-10-28 07:08:19 UTC · 2 stars

CVE-2023-33246 - Apache RocketMQ config RCE

AiK1d/CVE-2023-33246

github · Created 2023-06-02 01:41:12 UTC · 2 stars

CVE-2023-33246:Apache RocketMQ 远程命令执行漏洞检测工具

Malayke/CVE-2023-33246_RocketMQ_RCE_EXPLOIT

github · Created 2023-06-01 14:48:26 UTC · 100 stars

CVE-2023-33246 RocketMQ RCE Detect By Version and Exploit

SuperZero/CVE-2023-33246

github · Created 2023-06-01 06:27:09 UTC · 106 stars

Apache RocketMQ 远程代码执行漏洞(CVE-2023-33246) Exploit

Le1a/CVE-2023-33246

github · Created 2023-06-01 02:17:20 UTC · 80 stars

Apache RocketMQ 远程代码执行漏洞(CVE-2023-33246) Exploit

4mazing/CVE-2023-33246-Copy

github · Created 2023-05-31 07:28:46 UTC · 2 stars

I5N0rth/CVE-2023-33246

github · Created 2023-05-30 02:18:29 UTC · 62 stars

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Detected by Nuclei

  • Detected by Metasploit