CVE-2023-33246
About
For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution.
Several components of RocketMQ, including NameServer, Broker, and Controller, are leaked on the extranet and lack permission verification, an attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as. Additionally, an attacker can achieve the same effect by forging the RocketMQ protocol content.
To prevent these attacks, users are recommended to upgrade to version 5.1.1 or above for using RocketMQ 5.x or 4.9.6 or above for using RocketMQ 4.x .
Rainforest analyst review
Several RocketMQ components — the NameServer, Broker, and Controller — expose management functionality on their network ports without permission checks. When those ports are reachable, an attacker abuses the broker's update-configuration function to overwrite runtime settings, and by pointing the configuration at attacker-controlled input can cause commands to run as the system user that RocketMQ runs as. The same effect is achievable by forging RocketMQ protocol messages directly, so exploitation needs nothing more than network access to an exposed component.
The core exposure is that RocketMQ's ports are often left open to untrusted networks with no authentication layer in front, and because the broker runs with meaningful system privileges, code execution there is a direct route into the messaging backbone and the hosts around it. A public exploit appeared quickly and the flaw saw active scanning and exploitation, earning its place on CISA's KEV list. Upgrade to 5.1.1 or later on the 5.x line, or 4.9.6 or later on 4.x, and firewall NameServer and Broker ports so they are never exposed beyond trusted infrastructure.
References
- http://packetstormsecurity.com/files/173339/Apache-RocketMQ-5.1.0-Arbitrary-Code-Injection.html
- http://www.openwall.com/lists/oss-security/2023/07/12/1
- https://lists.apache.org/thread/1s8j2c8kogthtpv3060yddk03zq0pxyp
- https://www.vicarius.io/vsociety/posts/rocketmq-rce-cve-2023-33246-33247
- https://github.com/Malayke/CVE-2023-33246_RocketMQ_RCE_EXPLOIT
- https://github.com/jakabakos/CVE-2023-33246_Apache_RocketMQ_RCE
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-33246
Related CVEs
Frequently asked questions
What is CVE-2023-33246?
For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution. Several components of RocketMQ, including NameServer, Broker, and Controller, are leaked on the extranet and lack permission verification, an attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as.
How severe is CVE-2023-33246?
CVE-2023-33246 carries a CVSS 3.1 base score of 9.8, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 99 out of 100, in the critical band.
How is CVE-2023-33246 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.
Which products are affected by CVE-2023-33246?
Public advisories list the following as affected: rocketmq. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2023-33246?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
