CVE-2023-34050

    Dashboard / Vulnerabilities / CVE-2023-34050

    CVE-2023-34050

    Published: 19 Oct 2023Last Modified: 12 Aug 2026

    Summary: Spring AMQP Deserialization Vulnerability

    Details: In spring AMQP versions 1.0.0 to 2.4.16 and 3.0.0 to 3.0.9 , allowed list patterns for deserializable class names were added to Spring AMQP, allowing users to lock down deserialization of data in messages from untrusted sources; however by default, when no allowed list was provided, all classes could be deserialized. Specifically, an application is vulnerable if * the SimpleMessageConverter or SerializerMessageConverter is used * the user does not configure allowed list patterns * untrusted message originators gain permissions to write messages to the RabbitMQ broker to send malicious content

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 8ae9f4fd5a1a90ad912a2aa1dce147f993202655

    Affected versions

    v3.0.8
    v3.0.7
    v3.0.6
    v3.0.5
    v3.0.4
    v3.0.3
    v3.0.2
    v3.0.1
    v3.0.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2023-34050 | CVE-DB