CVE-2017-8045: Critical severity spring amqp vulnerability
In Pivotal Spring AMQP versions prior to 1.7.4, 1.6.11, and 1.5.7, an org.springframework.amqp.core.Message may be unsafely deserialized when being converted into a string. A malicious payload could be crafted to exploit this and enable a remote code execution attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-8045?
The severity of CVE-2017-8045 is critical with a severity value of 9.8.
How does CVE-2017-8045 affect Pivotal Spring AMQP?
CVE-2017-8045 affects Pivotal Spring AMQP versions prior to 1.7.4, 1.6.11, and 1.5.7.
What is the vulnerability description for CVE-2017-8045?
CVE-2017-8045 allows a malicious payload to be crafted which may enable remote code execution by exploiting unsafe deserialization of org.springframework.amqp.core.Message.
How can I fix CVE-2017-8045?
To fix CVE-2017-8045, update Pivotal Spring AMQP to version 1.7.4, 1.6.11, or 1.5.7.
Are there any references for CVE-2017-8045?
Yes, you can find more information about CVE-2017-8045 at the following references: http://www.securityfocus.com/bid/100936, https://pivotal.io/security/cve-2017-8045.