SB2020051438 - Path traversal in Apache RocketMQ



SB2020051438 - Path traversal in Apache RocketMQ

Published: May 14, 2020 Updated: May 24, 2023

Security Bulletin ID SB2020051438
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Path traversal (CVE-ID: CVE-2019-17572)

The vulnerability allows a remote user to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences when the automatic topic creation in the broker is turned on. A remote user can force the application to create folders in the parent directory in brokers using a specially crafted topic name.


Remediation

Install update from vendor's website.