EXPOSURES › CVE-2023-33246
CVE-2023-33246
HIGH ⌖ ON CISA KEV · EXPLOITEDApache RocketMQ's exposed components lacked permission checks, allowing command execution via configuration updates or forged protocol content, and is currently being exploited in the wild.
RocketMQ components (NameServer, Broker, Controller) were accessible externally without proper authorization, enabling attackers to execute commands as system users. DIB organizations using RocketMQ face potential data breaches, system compromise, and compliance failures (NIST 800-171 controls 3.AO.1, 3.CP.1). Immediately verify RocketMQ deployments, apply available patches, and review configuration settings.
Shame score — The vulnerability's exploitation in the wild and the ease of command execution due to missing basic permission checks demonstrate significant negligence.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Several components of Apache RocketMQ, including NameServer, Broker, and Controller, are exposed to the extranet and lack permission verification. An attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as or achieve the same effect by forging the RocketMQ protocol content.