Spring Advanced Message Queuing Protocol
spring_advanced_message_queuing_protocol
Vendor: Vmware • 10 CVEs
CVEs (10)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Vmware 1Spring Advanced Message Queuing Protocol Aug 31, 2026 Aug 27, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 When a container-level ErrorHandler is configured (the mitigation for finding 221000), each delivery whose processing throws still permanently consumes one link credit. After initialCredits (default 100) failing messages...Show more |
1Vmware 1Spring Advanced Message Queuing Protocol Sep 1, 2026 Aug 27, 2026 N/A· v4 6.8 MEDIUM· v3 N/A· v2 Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of every log event. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4...Show more |
1Vmware 1Spring Advanced Message Queuing Protocol Sep 1, 2026 Aug 27, 2026 N/A· v4 4.9 MEDIUM· v3 N/A· v2 A single hostile AMQP message can terminate the entire consumer JVM (System.exit(99)), not just the listener thread — full availability loss for every workload co-located in that process. Spring AMQP 4.1.0 Spring AMQP 4....Show more |
1Vmware 1Spring Advanced Message Queuing Protocol Sep 1, 2026 Aug 27, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 When the RabbitMQ management aliveness check fails, the configured admin password is embedded in cleartext in the thrown exception message. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AM...Show more |
1Vmware 1Spring Advanced Message Queuing Protocol Sep 2, 2026 Aug 27, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 An attacker who can publish to a queue consumed by an application that has enabled message decompression can crash the consumer JVM with a single ~1 MB message. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2...Show more |
1Vmware 1Spring Advanced Message Queuing Protocol Jul 17, 2026 Jun 10, 2026 N/A· v4 4.0 MEDIUM· v3 N/A· v2 Applications that configure their broker connection via RabbitConnectionFactoryBean.setUri("amqps://...") without also calling setUseSSL(true) get TLS encryption with no certificate validation and no hostname verificatio...Show more |
1Vmware 1Spring Advanced Message Queuing Protocol Jun 17, 2026 Oct 19, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 In spring AMQP versions 1.0.0 to 2.4.16 and 3.0.0 to 3.0.9 , allowed list patterns for deserializable class names were added to Spring AMQP, allowing users to lock down deserialization of data in messages from...Show more |
1Vmware 1Spring Advanced Message Queuing Protocol Jun 17, 2026 Nov 30, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In Spring AMQP versions 2.2.0 - 2.2.19 and 2.3.0 - 2.3.11, the Spring AMQP Message object, in its toString() method, will create a new String object from the message body, regardless of its size. This can cause an OOM Er...Show more |
1Vmware 1Spring Advanced Message Queuing Protocol Jun 17, 2026 Oct 28, 2021 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 In Spring AMQP versions 2.2.0 - 2.2.18 and 2.3.0 - 2.3.10, the Spring AMQP Message object, in its toString() method, will deserialize a body for a message with content type application/x-java-serialized-object. It is pos...Show more |
2Fedoraproject Vmware2Fedora Spring Advanced Message Queuing ProtocolMay 13, 2026 Apr 21, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 org.springframework.core.serializer.DefaultDeserializer in Spring AMQP before 1.5.5 allows remote attackers to execute arbitrary code. |