Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
vmware spring advanced message queuing protocol vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2016-2173
org.springframework.core.serializer.DefaultDeserializer in Spring AMQP prior to 1.5.5 allows remote malicious users to execute arbitrary code.
Fedoraproject Fedora 24
Fedoraproject Fedora 22
Fedoraproject Fedora 23
Vmware Spring Advanced Message Queuing Protocol
1 Github repository
6.5
CVSSv3
CVE-2021-22095
In Spring AMQP versions 2.2.0 - 2.2.19 and 2.3.0 - 2.3.11, the Spring AMQP Message object, in its toString() method, will create a new String object from the message body, regardless of its size. This can cause an OOM Error with a large message
Vmware Spring Advanced Message Queuing Protocol
6.5
CVSSv3
CVE-2021-22097
In Spring AMQP versions 2.2.0 - 2.2.18 and 2.3.0 - 2.3.10, the Spring AMQP Message object, in its toString() method, will deserialize a body for a message with content type application/x-java-serialized-object. It is possible to construct a malicious java.util.Dictionary object t...
Vmware Spring Advanced Message Queuing Protocol
4.3
CVSSv3
CVE-2023-34050
In spring AMQP versions 1.0.0 to 2.4.16 and 3.0.0 to 3.0.9 , allowed list patterns for deserializable class names were added to Spring AMQP, allowing users to lock down deserialization of data in messages from untrusted sources; however by default, when no allowed list was provi...
Vmware Spring Advanced Message Queuing Protocol
1 Github repository
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4651
CVE-2024-34255
elevation of privilege
CVE-2024-25529
CVE-2024-4671
NULL pointer dereference
CVE-2024-25527
template injection
CVE-2008-0166
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started