QID 982817
QID 982817: Java (maven) Security Update for org.apache.rocketmq:rocketmq-broker (GHSA-5x3v-2gxr-59m2)
In Apache RocketMQ 4.2.0 to 4.6.0, when the automatic topic creation in the broker is turned on by default, an evil topic like ../../../../topic2020 is sent from rocketmq-client to the broker, a topic folder will be created in the parent directory in brokers, which leads to a directory traversal vulnerability. Users of the affected versions should apply one of the following: Upgrade to Apache RocketMQ 4.6.1 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-5x3v-2gxr-59m2 for updates pertaining to this vulnerability.
Vendor References
- GHSA-5x3v-2gxr-59m2 -
github.com/advisories/GHSA-5x3v-2gxr-59m2
CVEs related to QID 982817
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-5x3v-2gxr-59m2 | org.apache.rocketmq:rocketmq-broker |
|