Vulnerability record · CVE-2023-37582 · published 12 July 2023
CVE-2023-37582: Apache RocketMQ NameServer incomplete fix allows remote command execution
Apache · Rocketmq
CVE-2023-37582 is a remote command execution flaw in the Apache RocketMQ NameServer component, arising because the fix for CVE-2023-33246 was incomplete in version 5.1.1. When a NameServer address is exposed and lacks permission verification, an attacker can abuse the update configuration function to run commands as the RocketMQ service account.
Description
The RocketMQ NameServer component still has a remote command execution vulnerability as the CVE-2023-33246 issue was not completely fixed in version 5.1.1. When NameServer address are leaked on the extranet and lack permission verification, an attacker can exploit this vulnerability by using the update configuration function on the NameServer component to execute commands as the system users that RocketMQ is running as. It is recommended for users to upgrade their NameServer version to 5.1.2 or above for RocketMQ 5.x or 4.9.7 or above for RocketMQ 4.x to prevent these attacks.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication or interaction required, and very high EPSS probability make this a top remediation priority despite no KEV listing.
What it is
CVE-2023-37582 is a remote command execution flaw in the Apache RocketMQ NameServer component, arising because the fix for CVE-2023-33246 was incomplete in version 5.1.1. When a NameServer address is exposed and lacks permission verification, an attacker can abuse the update configuration function to run commands as the RocketMQ service account.
Impact
An attacker gains arbitrary command execution with the privileges of the RocketMQ system user, which can lead to full compromise of the host and any data or services it can reach.
Attack surface
Reachable over the network via the NameServer component when its address is exposed to the extranet and permission verification is absent; the CVSS vector indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented, but EPSS is very high at 0.904 (99.8th percentile), and references are patch and advisory only with no public exploit tag.
What to do
- Upgrade RocketMQ NameServer to 5.1.2 or above for 5.x, or 4.9.7 or above for 4.x, as the vendor recommends.
- Do not expose NameServer addresses to untrusted networks; restrict access with firewall rules or network segmentation.
- Enable and enforce permission verification on the NameServer component where supported.
- Run RocketMQ under a least-privileged dedicated service account to limit command execution impact.
- Monitor for unexpected configuration changes on NameServer instances.
Detection
- Alert on NameServer update configuration requests originating from unexpected or external source addresses.
- Monitor RocketMQ service account processes for anomalous child processes or command execution.
- Review network logs for external connections to NameServer ports that should be internal only.
- Audit NameServer configuration changes and correlate them with process execution events.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.openwall.com/lists/oss-security/2023/07/12/1 | Mailing ListPatchThird Party Advisory |
| https://lists.apache.org/thread/m614czxtpvlztd7mfgcs2xcsg36rdbnc | Mailing ListPatchVendor Advisory |
| http://www.openwall.com/lists/oss-security/2023/07/12/1 | Mailing ListPatchThird Party Advisory |
| https://lists.apache.org/thread/m614czxtpvlztd7mfgcs2xcsg36rdbnc | Mailing ListPatchVendor Advisory |
Track CVE-2023-37582 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-37582), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.