[Information Security Daily] On January 8, the distributed message streaming data platform Apache RocketMQ had a major and incompletely patched vulnerability.
The team that developed the distributed message streaming data platform Apache RocketMQ discovered that the major vulnerability CVE-2023-33246 they patched in May this year was incompletely patched, and a new version of the program component was provided to patch it.
It is worth noting that according to the Shadowserver Foundation’s investigation, they have currently published the geographical locations of hosts exposed on the Internet to the foundation’s global security situation database, and stated that hackers have passed nearly 400 source IP address to try to exploit the above two vulnerabilities.