Missing Authorization in RocketMQ - CVE-2023-33246
Published: May 24, 2023 / Updated: August 31, 2023
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to missing authorization in several components of RocketMQ, including NameServer, Broker, and Controller. A remote non-authenticated attacker can use the update configuration function to execute arbitrary commands on the system. Additionally, an attacker can achieve the same effect by forging the RocketMQ protocol content.
Affected software
IBM Observability with Instana
How to mitigate CVE-2023-33246
IBM Observability with Instana - update to 255
Links to Public Exploits and PoC-codes
- Exploit #9176 - Apache RocketMQ update config RCE (July 6, 2023)
- Exploit #9159 - CVE-2023-33246 () (June 27, 2023)
- Exploit #9109 - CVE-2023-33246 (Apache RocketMQ 远程代码执行漏洞(CVE-2023-33246) Exploit) (June 14, 2023)
- Exploit #9108 - CVE-2023-33246 (Apache RocketMQ 远程代码执行漏洞(CVE-2023-33246) Exploit) (June 14, 2023)
- Exploit #9106 - CVE-2023-33246_RocketMQ_RCE_EXPLOIT (CVE-2023-33246 RocketMQ RCE Detect By Version and Exploit) (June 14, 2023)