CVE-2019-17572
Directory traversal in Apache RocketMQ
EPSS 1.5%
Description
In Apache RocketMQ 4.2.0 to 4.6.0, when the automatic topic creation in the broker is turned on by default, an evil topic like “../../../../topic2020” is sent from rocketmq-client to the broker, a topic folder will be created in the parent directory in brokers, which leads to a directory traversal vulnerability. Users of the affected versions should apply one of the following: Upgrade to Apache RocketMQ 4.6.1 or later.
How to fix CVE-2019-17572
To remediate CVE-2019-17572, upgrade the affected package to a fixed version below.
- Maven/org.apache.rocketmq:rocketmq-broker—upgrade to 4.6.1 or later
Is CVE-2019-17572 being exploited?
Low — EPSS is 1.5%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 4.2.0, < 4.6.1