GHSA-x3cq-8f32-5f63 · Severity: critical · Ecosystem: maven — Apache RocketMQ may have remote code execution vulnerability when using update configuration function
For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution. Several components of RocketMQ, including NameServer, Broker, and Controller, are leaked on the extranet and lack permission verification, an attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as. Additionally, an attacker can achieve the same effect by forging the RocketMQ protocol content. To prevent these attacks, users are recommended to upgrade to version 5.1.1 or above for using RocketMQ 5.x or 4.9.6 or above for using RocketMQ 4.x .
Conclusion & alert: CVE-2023-33246 is rated Critical Active Threat (99.4/100): CVSS Critical severity, with high exploitation likelihood (EPSS 94.39%, 100th percentile). Core evidence: CISA KEV confirms active exploitation (added 2023-09-06) affecting Apache / RocketMQ. a weakness (CWE-94) Unauthenticated remote administrative access may be possible. Mandatory action: The CISA remediation deadline has passed—treat as an emergency patch priority.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
: Apache RocketMQ Command Execution Vulnerability · CISA KEV detail
: 2023-09-06
: 2023-09-27
: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-11-21 | 94.14% | 94.39% | +0.25% |
| 2 | 2025-11-18 | 94.43% | 94.14% | -0.29% |
| 3 | 2025-04-15 | — | 94.43% | — |
Full EPSS history (29 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
GHSA-x3cq-8f32-5f63 · Severity: critical · Ecosystem: maven — Apache RocketMQ may have remote code execution vulnerability when using update configuration function
| vendor | priority | summary | link |
|---|---|---|---|
redhat
|
critical | — | https://access.redhat.com/security/cve/CVE-2023-33246 |
| URL | Tags |
|---|---|
| http://packetstormsecurity.com/files/173339/Apache-RocketMQ-5.1.0-Arbitrary-Code-Injection.html | Exploit Third Party Advisory VDB Entry |
| http://www.openwall.com/lists/oss-security/2023/07/12/1 | Mailing List Third Party Advisory |
| https://lists.apache.org/thread/1s8j2c8kogthtpv3060yddk03zq0pxyp | Mailing List Vendor Advisory |
| https://www.vicarius.io/vsociety/posts/rocketmq-rce-cve-2023-33246-33247 | Exploit Third Party Advisory |
| https://github.com/Malayke/CVE-2023-33246_RocketMQ_RCE_EXPLOIT | Exploit |
| https://github.com/jakabakos/CVE-2023-33246_Apache_RocketMQ_RCE | Exploit |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-33246 | Third Party Advisory US Government Resource |