apache rocketmq CVE-2019-17572 is a vulnerability in Apache RocketMQ
Published on May 14, 2020

In Apache RocketMQ 4.2.0 to 4.6.0, when the automatic topic creation in the broker is turned on by default, an evil topic like ../../../../topic2020 is sent from rocketmq-client to the broker, a topic folder will be created in the parent directory in brokers, which leads to a directory traversal vulnerability. Users of the affected versions should apply one of the following: Upgrade to Apache RocketMQ 4.6.1 or later.

NVD


Products Associated with CVE-2019-17572

Want to know whenever a new CVE is published for Apache RocketMQ? stack.watch will email you.

 

Exploit Probability

EPSS
1.55%
Percentile
81.20%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.