Security News > 2023 > September > CISA warns of critical Apache RocketMQ bug exploited in attacks
![CISA warns of critical Apache RocketMQ bug exploited in attacks](/static/build/img/news/cisa-warns-of-critical-apache-rocketmq-bug-exploited-in-attacks-medium.jpg)
The U.S. Cybersecurity and Infrastructure Security Agency has added to its catalog of known exploited vulnerabilities a critical-severity issue tracked as CVE-2023-33246 that affects Apache's RocketMQ distributed messaging and streaming platform.
CISA is warning federal agencies that they should patch the CVE-2023-33246 vulnerability for Apache RocketMQ installations on their systems by September 27.
The cybersecurity agency notes that an attacker can exploit the issue "By using the update configuration function to execute commands as the system users that RocketMQ is running."
Leveraging the issue is possible because multiple RocketMQ components that include NameServer, Broker, and Controller, are exposed on the public internet, making them a target for hackers.
Trying to find how many potential RocketMQ targets are exposed online, the researcher looked for hosts with the TCP port 9876 used by the RocketMQ Nameserver and found about 4,500 systems.
CISA warns of critical Citrix ShareFile flaw exploited in the wild.
News URL
Related news
- CISA warns critical Geoserver GeoTools RCE flaw is exploited in attacks (source)
- Critical Apache HugeGraph Vulnerability Under Attack - Patch ASAP (source)
- London hospitals left in critical condition after ransomware attack (source)
- Muhstik Botnet Exploiting Apache RocketMQ Flaw to Expand DDoS Attacks (source)
- CISA warns of Windows bug exploited in ransomware attacks (source)
- CISA: Most critical open source projects not using memory safe code (source)
- Critical Flaws in CocoaPods Expose iOS and macOS Apps to Supply Chain Attacks (source)
- Critical vulnerability in the RADIUS protocol leaves networking equipment open to attack (source)
- Critical Windows licensing bugs, plus two others under attack, top Patch Tuesday (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-05-24 | CVE-2023-33246 | Code Injection vulnerability in Apache Rocketmq For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution. Several components of RocketMQ, including NameServer, Broker, and Controller, are leaked on the extranet and lack permission verification, an attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as. | 9.8 |