Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40683
HistoryMay 25, 2023 - 2:04 a.m.

Remote Code Execution (RCE)

2023-05-2502:04:34
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
19
rocketmq
remote code execution
vulnerability
configuration path
injection
malicious code
protocol content
information leakage
extranet

0.973 High

EPSS

Percentile

99.9%

RocketMQ is vulnerable to Remote Code Execution (RCE). The vulnerability exists because the library allows updating the config path at runtime, allowing an attacker to inject and execute malicious code through the update configuration function by forging the RocketMQ protocol content, which also leads to information leakage in the extranet.