Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreThe Spring AMQP Message object, in its toString() method, will deserialize a body for a message with content type application/x-java-serialized-object. Classes in the java.lang and java.util packages are trusted.
It is possible to construct a malicious java.util.Dictionary object that can cause 100% CPU usage in the application if the toString() method is called.
This requires the attacker to have privileges to directly publish messages with such a body to the RabbitMQ server.
Spring AMQP:
| Fix version | Availability |
|---|---|
| 2.3.11 | OSS |
| 2.2.19.RELEASE | OSS |
Do not allow untrustworthy actors to publish arbitrary data to RabbitMQ. No other steps are necessary.
This issue was identified and responsibly reported by r00t4dm Cloud-Penetrating Arrow Lab of Meituan Corp Information Security Department.
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy