漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
In Apache RocketMQ 4.2.0 to 4.6.0, when the automatic topic creation in the broker is turned on by default, an evil topic like “../../../../topic2020” is sent from rocketmq-client to the broker, a topic folder will be created in the parent directory in brokers, which leads to a directory traversal vulnerability. Users of the affected versions should apply one of the following: Upgrade to Apache RocketMQ 4.6.1 or later.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apache RocketMQ 路径遍历漏洞
Vulnerability Description
Apache RocketMQ是美国阿帕奇软件(Apache Software)基金会的一款轻量级的数据处理平台和消息传递引擎。 Apache RocketMQ 4.2.0版本至4.6.0版本中存在路径遍历漏洞。攻击者可利用该漏洞在父目录中创建主体文件夹。
CVSS Information
N/A
Vulnerability Type
N/A