July 7, 2023, 7:26 p.m. | Dean Welch

Rapid7 Blog blog.rapid7.com

Apache RocketMQ


We saw some great teamwork this week from jheysel-r7 and h00die to bring you an exploit module for CVE-2023-33246.

In Apache RocketMQ version 5.1.0 and under, there is an access control issue which the module leverages to update the broker's configuration file without authentication. From here

access access control apache authentication configuration control cve exploit file great issue metasploit metasploit weekly wrapup teamwork under update version week weekly wrap-up

Cyber Security Engineer

@ ASSYSTEM | Bridgwater, United Kingdom

Security Analyst

@ Northwestern Memorial Healthcare | Chicago, IL, United States

GRC Analyst

@ Richemont | Shelton, CT, US

Security Specialist

@ Peraton | Government Site, MD, United States

Information Assurance Security Specialist (IASS)

@ OBXtek Inc. | United States

Cyber Security Technology Analyst

@ Airbus | Bengaluru (Airbus)