Security readout for executives and security teams
Plain-English summary
Apache RocketMQ versions 4.2.0 through 4.6.0 can create topic folders outside the intended broker directory when automatic topic creation is enabled. This is a directory traversal issue. The provided sources name an upgrade path to 4.6.1 or later but do not provide CVSS scoring or evidence of active exploitation.
Executive priority
Prioritize remediation for internet-exposed or multi-tenant RocketMQ brokers first. The business risk is configuration-dependent, but the fix is clear: move affected brokers to 4.6.1 or later.
Technical view
When a RocketMQ client sends a specially formed topic name and broker automatic topic creation is enabled, affected brokers may create a topic folder in a parent directory. The affected range is Apache RocketMQ 4.2.0 to 4.6.0. The stated remediation is upgrading to Apache RocketMQ 4.6.1 or later.
Likely exposure
Exposure is most likely where Apache RocketMQ brokers run versions 4.2.0 through 4.6.0 with automatic topic creation enabled. Risk depends on whether untrusted or weakly governed clients can submit topic names to brokers.
Exploitation context
The source bundle describes the vulnerable condition but does not cite public exploitation, weaponized tooling, or CISA KEV listing. Treat exploitation status as unconfirmed from the provided evidence.
Researcher notes
The provided record does not include CVSS, CWE, authentication requirements, or full impact beyond unintended parent-directory folder creation. Avoid assuming code execution, file overwrite, or confirmed compromise without additional vendor or incident evidence.
Mitigation direction
- Upgrade Apache RocketMQ to 4.6.1 or later.
- Inventory RocketMQ broker versions across production and non-production environments.
- Review broker automatic topic creation exposure against vendor guidance.
- Limit broker access to trusted clients according to existing network policy.
- Monitor vendor advisories for any additional hardening guidance.
Validation and detection
- Confirm no brokers run Apache RocketMQ 4.2.0 through 4.6.0.
- Verify upgraded brokers report version 4.6.1 or later.
- Check whether automatic topic creation is enabled on broker configurations.
- Review topic directories for unexpected parent-directory folder creation.
- Confirm client access controls match intended trusted-client boundaries.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
File access behavior lookup
The CVE wording references file access or upload behavior, so file telemetry and web shell review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
Open ATT&CK lookupCVE-2019-17572 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://lists.apache.org/thread.html/fdea1c5407da47a17d5522fa149a097cacded1916c1c1534d46edc6d%40%3Cprivate.rocketmq.apache.org%3ECVE reference · x_refsource_MISC
- https://seclists.org/oss-sec/2020/q2/112CVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
