Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreIn affected versions of Spring AMQP, a org.springframework.amqp.core.Message may be unsafely deserialized when being converted into a string. A malicious payload could be crafted to exploit this and enable a remote code execution attack.
Spring AMQP:
| Fix version | Availability |
|---|---|
| 1.7.4 | OSS |
| 1.6.11 | OSS |
| 1.5.7 | OSS |
No further mitigation steps are necessary.
This vulnerability was responsibly reported by Man Yue Mo from Semmle and lgtm.com.
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy