Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Apache RocketMQ 敏感信息泄露漏洞 #331

Open
foyaga opened this issue Jul 23, 2024 · 0 comments
Open

Apache RocketMQ 敏感信息泄露漏洞 #331

foyaga opened this issue Jul 23, 2024 · 0 comments
Labels
watchvuln watchvuln推送

Comments

@foyaga
Copy link
Owner

foyaga commented Jul 23, 2024

漏洞描述:

Apache RocketMQ 是一款开源的分布式消息系统。
受影响版本中存在敏感信息泄露漏洞,未经授权的用户可以在启用身份验证和授权功能的情况下获得敏感信息。拥有普通用户权限的攻击者可以通过特定接口窃取管理员账号和密码从而获得RocketMQ权限。
修复版本中,通过增加权限检查和验证,细化访问配置以修复漏洞。强烈建议将 RocketMQ ACL 升级为2.0。

参考链接:

  1. https://www.oscs1024.com/hd/MPS-ch3x-oesa
  2. [RIP-68] RocketMQ ACL 2.0 apache/rocketmq#7560
  3. [ISSUE #7560] [RIP-68] Support RocketMQ ACL 2.0  apache/rocketmq#7725
  4. apache/rocketmq@e1339ac
  5. https://nvd.nist.gov/vuln/detail/CVE-2024-23321
@foyaga foyaga added the watchvuln watchvuln推送 label Jul 23, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
watchvuln watchvuln推送
Projects
None yet
Development

No branches or pull requests

1 participant