Known vulnerabilities in RocketMQ
Vendor:
Apache Foundation
Software:
RocketMQ
Software CPE:
cpe:2.3:a:apache_foundation:rocketmq:*:*:*:*:*:*:*:*
Website:
https://www.apache.org
Total vulnerabilities:
4
Public exploits:
2
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (4)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU94766 - Exposure of sensitive information to an unauthorized actor CVE-2024-23321 |
CWE-200 | Medium | 5.3.0 | 26.07.2024 |
SB2024072650 |
||
| #VU78267 - Missing Authorization CVE-2023-37582 |
CWE-862 | High | 4.9.7, 5.1.2 | 15.07.2023 |
SB2023071508 |
||
| #VU76462 - Missing Authorization CVE-2023-33246 |
CWE-862 | Critical | 4.9.6, 5.1.1 | 24.05.2023 |
SB2023052415 SB2024020514 |
||
| #VU76461 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2019-17572 |
CWE-22 | Low | 4.6.1 | 24.05.2023 |
SB2020051438 |