Skip to main content

Vendor/product archive

apache / rocketmq CVEs

Beta · best-effort

4 CVEs tagged to apache / rocketmq2 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2024-23321

Published Jul 22, 2024

For RocketMQ versions 5.2.0 and below, under certain conditions, there is a risk of exposure of sensitive Information to an unauthorized actor even if RocketMQ is enabled with aut…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-37582

Published Jul 12, 2023

The RocketMQ NameServer component still has a remote command execution vulnerability as the CVE-2023-33246 issue was not completely fixed in version 5.1.1. When NameServer addre…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-33246

Published May 24, 2023

For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution.  Several components of RocketMQ, including NameServer, Broker, and C…

CVSS 9.8 · Critical
evidence mentions
5
Buzz score
55.9
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2019-17572

Published May 14, 2020

In Apache RocketMQ 4.2.0 to 4.6.0, when the automatic topic creation in the broker is turned on by default, an evil topic like “../../../../topic2020” is sent from rocketmq-client…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1