#VU94766 Information disclosure in RocketMQ - CVE-2024-23321
Published: July 26, 2024
RocketMQ
Apache Foundation
Description
The vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application if RocketMQ is enabled with authentication and authorization functions. A remote attacker possessing regular user privileges or listed in the IP whitelist can acquire the administrator's account and password through specific interfaces.