GHSA-5x3v-2gxr-59m2

Suggest an improvement
Source
https://github.com/advisories/GHSA-5x3v-2gxr-59m2
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/07/GHSA-5x3v-2gxr-59m2/GHSA-5x3v-2gxr-59m2.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-5x3v-2gxr-59m2
Aliases
Published
2020-07-01T17:26:15Z
Modified
2024-12-02T05:32:40.753141Z
Summary
Directory traversal in Apache RocketMQ
Details

In Apache RocketMQ 4.2.0 to 4.6.0, when the automatic topic creation in the broker is turned on by default, an evil topic like “../../../../topic2020” is sent from rocketmq-client to the broker, a topic folder will be created in the parent directory in brokers, which leads to a directory traversal vulnerability. Users of the affected versions should apply one of the following: Upgrade to Apache RocketMQ 4.6.1 or later.

Database specific
{
    "nvd_published_at": null,
    "cwe_ids": [
        "CWE-22"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2020-07-01T17:26:05Z"
}
References

Affected packages

Maven / org.apache.rocketmq:rocketmq-broker

Package

Name
org.apache.rocketmq:rocketmq-broker
View open source insights on deps.dev
Purl
pkg:maven/org.apache.rocketmq/rocketmq-broker

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.2.0
Fixed
4.6.1

Affected versions

4.*

4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.5.2
4.6.0