REDHAT-BUG-1326205: High severity spring amqp vulnerability
A remote code execution vulnerability was found in Spring AMQP. The class org.springframework.core.serializer.DefaultDeserializer does not validate the deserialized object against a whitelist. By supplying a crafted serialized object like Chris Frohoff's Commons Collection gadget, remote code execution can be achieved.
External references:
https://jira.spring.io/browse/AMQP-590 http://pivotal.io/security/cve-2016-2173
Upstream fix:
https://github.com/spring-projects/spring-amqp/commit/4150f107e60cac4a7735fcf7cb4c1889a0cbab6c
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1326205?
The severity of REDHAT-BUG-1326205 is critical due to its potential for remote code execution.
How do I fix REDHAT-BUG-1326205?
To fix REDHAT-BUG-1326205, update Spring AMQP to a version that contains the security patches for this vulnerability.
What software is affected by REDHAT-BUG-1326205?
REDHAT-BUG-1326205 affects the Spring AMQP framework.
What type of vulnerability is REDHAT-BUG-1326205?
REDHAT-BUG-1326205 is categorized as a remote code execution vulnerability.
What can an attacker do with REDHAT-BUG-1326205?
An attacker can exploit REDHAT-BUG-1326205 to execute arbitrary code on the server by sending a crafted serialized object.