CVE-2024-23321: Apache RocketMQ: Unauthorized Exposure of Sensitive Data

2024-07-22 Thread Rongtong Jin
Severity: moderate Affected versions: - Apache RocketMQ 4.5.2 through 5.2.0 Description: For RocketMQ versions 5.2.0 and below, under certain conditions, there is a risk of exposure of sensitive Information to an unauthorized actor even if RocketMQ is enabled with authentication and authoriza

Re: [D] Controller模式,重启后,发现主从不同步,报错信息:Failed to find a consistent point between masterEpoch: [rocketmq]

2024-07-22 Thread via GitHub
GitHub user lialatdd added a comment to the discussion: Controller模式,重启后,发现主从不同步,报错信息:Failed to find a consistent point between masterEpoch: 我这边部署5.1.3版本的controller+broker集群,一主一从的模式下,也出现了这个问题 GitHub link: https://github.com/apache/rocketmq/discussions/7674#discussioncomment-10120861 Th

Re: [D] Controller模式,重启后,发现主从不同步,报错信息:Failed to find a consistent point between masterEpoch: [rocketmq]

2024-07-22 Thread via GitHub
GitHub user lialatdd added a comment to the discussion: Controller模式,重启后,发现主从不同步,报错信息:Failed to find a consistent point between masterEpoch: ![image](https://github.com/user-attachments/assets/1a54702d-1133-4f93-9947-a2c0ee6c3a98) GitHub link: https://github.com/apache/rocketmq/discussions/

Re:[VOTE]Release Apache RocketMQ Spring 2.3.1 RC1

2024-07-22 Thread fuyou
+1 At 2024-07-22 10:10:04, "jinrongtong" wrote: >Hello RocketMQ Community, > >This is the vote for the 2.3.1 release of Apache RocketMQ-Spring. > > > >The artifacts: >https://dist.apache.org/repos/dist/dev/rocketmq/rocketmq-spring/2.3.1-rc1/ > > >The staging repo: >https://repository.apache.org/co

Re:[VOTE][RIP-70]Optimizing Lock Mechanisms

2024-07-22 Thread fuyou
+1. At 2024-07-14 08:42:36, "??" <3424672...@qq.com.INVALID> wrote: >Hi, RocketMQ Community, > > > > >As discussed in the previous email, we launched a new RIP 70 to Optimizing >Lock Mechanisms. Now the shepherds @RongtongJin is willing to support the RIP, >so I think it is time to start an e