Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTV4M3YtMmd4ci01OW0y
Directory traversal in Apache RocketMQ
In Apache RocketMQ 4.2.0 to 4.6.0, when the automatic topic creation in the broker is turned on by default, an evil topic like “../../../../topic2020” is sent from rocketmq-client to the broker, a topic folder will be created in the parent directory in brokers, which leads to a directory traversal vulnerability. Users of the affected versions should apply one of the following: Upgrade to Apache RocketMQ 4.6.1 or later.
Permalink: https://github.com/advisories/GHSA-5x3v-2gxr-59m2JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTV4M3YtMmd4ci01OW0y
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: over 4 years ago
Updated: almost 2 years ago
Identifiers: GHSA-5x3v-2gxr-59m2, CVE-2019-17572
References:
- https://nvd.nist.gov/vuln/detail/CVE-2019-17572
- https://github.com/apache/rocketmq/issues/1637
- https://github.com/apache/rocketmq/commit/f8f6fbe4aa7f5dee937e688322628c366b12a552
- https://lists.apache.org/thread.html/fdea1c5407da47a17d5522fa149a097cacded1916c1c1534d46edc6d%40%3Cprivate.rocketmq.apache.org%3E
- https://seclists.org/oss-sec/2020/q2/112
- https://snyk.io/vuln/SNYK-JAVA-ORGAPACHEROCKETMQ-569108
- https://github.com/advisories/GHSA-5x3v-2gxr-59m2
Blast Radius: 0.0
Affected Packages
maven:org.apache.rocketmq:rocketmq-broker
Dependent packages: 14Dependent repositories: 343
Downloads:
Affected Version Ranges: >= 4.2.0, < 4.6.1
Fixed in: 4.6.1
All affected versions: 4.2.0, 4.3.0, 4.3.1, 4.3.2, 4.4.0, 4.5.0, 4.5.1, 4.5.2, 4.6.0
All unaffected versions: 4.6.1, 4.7.0, 4.7.1, 4.8.0, 4.9.0, 4.9.1, 4.9.2, 4.9.3, 4.9.4, 4.9.5, 4.9.6, 4.9.7, 4.9.8, 5.0.0, 5.1.0, 5.1.1, 5.1.2, 5.1.3, 5.1.4, 5.2.0, 5.3.0, 5.3.1