[MAVEN:GHSA-HRP3-8P5W-27GV] Improper Input Validation in Spring AMQP

Severity Critical
Affected Packages 1
Fixed Packages 1
CVEs 1

org.springframework.core.serializer.DefaultDeserializer in Spring AMQP before 1.5.5 allows remote attackers to execute arbitrary code.

Package Affected Version
pkg:maven/org.springframework.amqp/spring-amqp <= 1.5.4
ID
MAVEN:GHSA-HRP3-8P5W-27GV
Severity
critical
URL
https://github.com/advisories/GHSA-hrp3-8p5w-27gv
Published
2022-05-13T01:26:13
(2 years ago)
Modified
2023-01-27T05:02:20
(20 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.springframework.amqp/spring-amqp org.springframework.amqp spring-amqp <= 1.5.4
Fixed pkg:maven/org.springframework.amqp/spring-amqp org.springframework.amqp spring-amqp = 1.5.5
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...