445
VMScore

CVE-2019-17572

Published: 14/05/2020 Updated: 15/05/2020
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

In Apache RocketMQ 4.2.0 to 4.6.0, when the automatic topic creation in the broker is turned on by default, an evil topic like “../../../../topic2020” is sent from rocketmq-client to the broker, a topic folder will be created in the parent directory in brokers, which leads to a directory traversal vulnerability. Users of the affected versions should apply one of the following: Upgrade to Apache RocketMQ 4.6.1 or later.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache rocketmq

Mailing Lists

Hi, An directory traversal vulnerability[1] was discovered in the version RocketMQ 460 and it affect all versions earlier And it was fixed[2] in the version 461 and later according to the CVE-2019-17572 Here is the detail of the vulnerability below: [CVEID]:CVE-2019-17572 [PRODUCT]:Apache RocketMQ [VERSIONS]:Apache RocketMQ 420 to 460 ...