Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTV4M3YtMmd4ci01OW0y

Directory traversal in Apache RocketMQ

In Apache RocketMQ 4.2.0 to 4.6.0, when the automatic topic creation in the broker is turned on by default, an evil topic like “../../../../topic2020” is sent from rocketmq-client to the broker, a topic folder will be created in the parent directory in brokers, which leads to a directory traversal vulnerability. Users of the affected versions should apply one of the following: Upgrade to Apache RocketMQ 4.6.1 or later.

Permalink: https://github.com/advisories/GHSA-5x3v-2gxr-59m2
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTV4M3YtMmd4ci01OW0y
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: over 4 years ago
Updated: almost 2 years ago


Identifiers: GHSA-5x3v-2gxr-59m2, CVE-2019-17572
References: Repository: https://github.com/apache/rocketmq
Blast Radius: 0.0

Affected Packages

maven:org.apache.rocketmq:rocketmq-broker
Dependent packages: 14
Dependent repositories: 343
Downloads:
Affected Version Ranges: >= 4.2.0, < 4.6.1
Fixed in: 4.6.1
All affected versions: 4.2.0, 4.3.0, 4.3.1, 4.3.2, 4.4.0, 4.5.0, 4.5.1, 4.5.2, 4.6.0
All unaffected versions: 4.6.1, 4.7.0, 4.7.1, 4.8.0, 4.9.0, 4.9.1, 4.9.2, 4.9.3, 4.9.4, 4.9.5, 4.9.6, 4.9.7, 4.9.8, 5.0.0, 5.1.0, 5.1.1, 5.1.2, 5.1.3, 5.1.4, 5.2.0, 5.3.0, 5.3.1