Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreAny application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of every log event. Attackers on the network path can read or alter log traffic (often containing tokens, PII, or stack traces with secrets) without certificate errors. The docs promise hostname verification is on by default, so operators have no reason to suspect exposure.
Spring AMQP:
| Fix version | Availability |
|---|---|
| 4.1.0.1 | Enterprise Support Only |
| 4.1.1 | OSS |
| 4.0.4.1 | Enterprise Support Only |
| 4.0.5 | OSS |
| 3.2.13 | Enterprise Support Only |
| 2.4.19 | Enterprise Support Only |
No further mitigation steps are necessary.
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy