Spring Advanced Message Queuing Protocol
spring_advanced_message_queuing_protocol
Vendor: Vmware • 5 CVEs
CVEs (5)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Vmware 1Spring Advanced Message Queuing Protocol Jul 17, 2026 Jun 10, 2026 N/A· v4 4.0 MEDIUM· v3 N/A· v2 Applications that configure their broker connection via RabbitConnectionFactoryBean.setUri("amqps://...") without also calling setUseSSL(true) get TLS encryption with no certificate validation and no hostname verificatio...Show more |
1Vmware 1Spring Advanced Message Queuing Protocol Jun 17, 2026 Oct 19, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 In spring AMQP versions 1.0.0 to 2.4.16 and 3.0.0 to 3.0.9 , allowed list patterns for deserializable class names were added to Spring AMQP, allowing users to lock down deserialization of data in messages from...Show more |
1Vmware 1Spring Advanced Message Queuing Protocol Jun 17, 2026 Nov 30, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In Spring AMQP versions 2.2.0 - 2.2.19 and 2.3.0 - 2.3.11, the Spring AMQP Message object, in its toString() method, will create a new String object from the message body, regardless of its size. This can cause an OOM Er...Show more |
1Vmware 1Spring Advanced Message Queuing Protocol Jun 17, 2026 Oct 28, 2021 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 In Spring AMQP versions 2.2.0 - 2.2.18 and 2.3.0 - 2.3.10, the Spring AMQP Message object, in its toString() method, will deserialize a body for a message with content type application/x-java-serialized-object. It is pos...Show more |
2Fedoraproject Vmware2Fedora Spring Advanced Message Queuing ProtocolMay 13, 2026 Apr 21, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 org.springframework.core.serializer.DefaultDeserializer in Spring AMQP before 1.5.5 allows remote attackers to execute arbitrary code. |