AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2024-23321

HIGH · CVSS 8.8 EPSS 0.89%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2024-07-22 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.8. It affects Apache.

CVE
CVE-2024-23321
Severity
HIGH
CVSS
8.8
EPSS
0.89%
Apache

Original NVD Description

For RocketMQ versions 5.2.0 and below, under certain conditions, there is a risk of exposure of sensitive Information to an unauthorized actor even if RocketMQ is enabled with authentication and authorization functions. An attacker, possessing regular user privileges or listed in the IP whitelist, could potentially acquire the administrator's account and password through specific interfaces. Such an action would grant them full control over RocketMQ, provided they have access to the broker IP address list. To mitigate these security threats, it is strongly advised that users upgrade to version 5.3.0 or newer. Additionally, we recommend users to use RocketMQ ACL 2.0 instead of the original RocketMQ ACL when upgrading to version Apache RocketMQ 5.3.0.

Related CVEs

Other vulnerabilities affecting the same vendor(s)