Skip to content
COOEY

EXPOSURES › CVE-2023-33246

CVE-2023-33246

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-09-06 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-33246 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

Apache RocketMQ's exposed components lacked permission checks, allowing command execution via configuration updates or forged protocol content, and is currently being exploited in the wild.

RocketMQ components (NameServer, Broker, Controller) were accessible externally without proper authorization, enabling attackers to execute commands as system users. DIB organizations using RocketMQ face potential data breaches, system compromise, and compliance failures (NIST 800-171 controls 3.AO.1, 3.CP.1). Immediately verify RocketMQ deployments, apply available patches, and review configuration settings.

Shame score — The vulnerability's exploitation in the wild and the ease of command execution due to missing basic permission checks demonstrate significant negligence.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Several components of Apache RocketMQ, including NameServer, Broker, and Controller, are exposed to the extranet and lack permission verification. An attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as or achieve the same effect by forging the RocketMQ protocol content.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.