CVE-2019-17572 Information
Feb 14, 2021
cve
Description
In Apache RocketMQ 4.2.0 to 4.6.0 when the automatic topic creation in the broker is turned on by default an evil topic like “../../../../topic2020” is sent from rocketmq-client to the broker a topic folder will be created in the parent directory in brokers which leads to a directory traversal vulnerability. Users of the affected versions should apply one of the following: Upgrade to Apache RocketMQ 4.6.1 or later.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Reference
https://lists.apache.org/thread.html/fdea1c5407da47a17d5522fa149a097cacded1916c1c1534d46edc6d403Cprivate.rocketmq.apache.org3E https://seclists.org/oss-sec/2020/q2/112
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
5.3
Share on: