org.springframework.amqp:spring-amqp
Maven5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.springframework.amqp:spring-amqppage 1 of 1
- CVE-2016-2173CRITICALCVSS 9.8EG 9.8✓ Fixed in 1.5.52017-04-21
vulnerable: 1.0.0.RELEASE ... 1.5.4.RELEASE (31 versions)
org.springframework.core.serializer.DefaultDeserializer in Spring AMQP before 1.5.5 allows remote attackers to execute arbitrary code.
- CVE-2017-8045CRITICALCVSS 9.8EG 9.8✓ Fixed in 1.7.42017-11-27
vulnerable: 1.7.0.RELEASE, 1.7.1.RELEASE, 1.7.2.RELEASE, 1.7.3.RELEASE
In Pivotal Spring AMQP versions prior to 1.7.4, 1.6.11, and 1.5.7, an org.springframework.amqp.core.Message may be unsafely deserialized when being converted into a string. A malicious payload could be crafted to exploit this and enable a …
- CVE-2018-11087MEDIUMCVSS 5.9EG 5.9✓ Fixed in 1.7.102018-09-14
vulnerable: 1.0.0.RELEASE ... 1.7.9.RELEASE (56 versions)
Pivotal Spring AMQP, 1.x versions prior to 1.7.10 and 2.x versions prior to 2.0.6, expose a man-in-the-middle vulnerability due to lack of hostname validation. A malicious user that has the ability to intercept traffic would be able to vie…
- CVE-2021-22095MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2.3.112021-11-30
vulnerable: 2.3.0 ... 2.3.9 (11 versions)
In Spring AMQP versions 2.2.0 - 2.2.19 and 2.3.0 - 2.3.11, the Spring AMQP Message object, in its toString() method, will create a new String object from the message body, regardless of its size. This can cause an OOM Error with a large me…
- CVE-2021-22097MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2.3.112021-10-28
vulnerable: 2.3.0 ... 2.3.9 (11 versions)
In Spring AMQP versions 2.2.0 - 2.2.18 and 2.3.0 - 2.3.10, the Spring AMQP Message object, in its toString() method, will deserialize a body for a message with content type application/x-java-serialized-object. It is possible to construct …
Check whether org.springframework.amqp:spring-amqp is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.springframework.amqp:spring-amqp CVEs against the assets you own.
Start Free Scan →