Filtered by CWE-94
Total 3861 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2023-33426 2023-05-24 9.8 Critical
A vulnerability was found in Apache RocketMQ where, under certain conditions, there is a risk of remote command execution. Several components of RocketMQ, including NameServer, Broker, and Controller, are leaked on the extranet and lack permission verification. This flaw allows an attacker to use the update configuration function to execute commands as the system users that RocketMQ is running as.