CVE Feed

    Dashboard / CVE / CVE-2023-34050

    CVE-2023-34050

    In spring AMQP versions 1.0.0 to 2.4.16 and 3.0.0 to 3.0.9 , allowed list patterns for deserializable class names were added to Spring AMQP, allowing users to lock down deserialization of data in messages from untrusted sources; however by default, when no allowed list was provided, all classes could be deserialized. Specifically, an application is vulnerable if * the SimpleMessageConverter or SerializerMessageConverter is used * the user does not configure allowed list patterns * untrusted message originators gain permissions to write messages to the RabbitMQ broker to send malicious content

    Published:Oct 19, 2023
    Last Modified:Nov 21, 2024
    EPS:Oct 19, 2023
    EPSS Score:0.44668
    CVSS Score:5

    Affected Products

    Vendor
    Redhat
    Product
    Amq Clients
    Vendor
    Vmware
    Product
    Spring Advanced Message Queuing Protocol

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High