Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-42971
HistoryMay 28, 2023 - 12:00 a.m.

Apache RocketMQ Command Execution Vulnerability

2023-05-2800:00:00
China National Vulnerability Database
www.cnvd.org.cn
14
apache rocketmq
command execution
vulnerability
data processing platform
messaging engine
configuration function
system user

0.973 High

EPSS

Percentile

99.9%

Apache RocketMQ is the United States Apache (Apache) Foundation of a lightweight data processing platform and messaging engine. A command execution vulnerability exists in Apache RocketMQ 5.1.0 and prior versions, which stems from an application failing to properly filter special elements of constructed snippets. An attacker can exploit the vulnerability to update the configuration function to execute commands as the system user.

CPENameOperatorVersion
apache rocketmqle5.1.0