cbcvebase.
CVE-2023-34050
published 2023-10-19

CVE-2023-34050: In spring AMQP versions 1.0.0 to 2.4.16 and 3.0.0 to 3.0.9 , allowed list patterns for deserializable class names were added to Spring AMQP, allowing users to…

PriorityP423medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
EPSS
1.54%
72.1th percentile
In spring AMQP versions 1.0.0 to
2.4.16 and 3.0.0 to 3.0.9 , allowed list patterns for deserializable class
names were added to Spring AMQP, allowing users to lock down deserialization of
data in messages from untrusted sources; however by default, when no allowed
list was provided, all classes could be deserialized.


Specifically, an application is
vulnerable if


* the
SimpleMessageConverter or SerializerMessageConverter is used

* the user
does not configure allowed list patterns

* untrusted
message originators gain permissions to write messages to the RabbitMQ
broker to send malicious content

Affected

4 ranges
VendorProductVersion rangeFixed in
springspring_amqp>= 1.0.0 < 2.4.172.4.17
springspring_amqp>= 3.0.0 < 3.0.103.0.10
vmwarespring_advanced_message_queuing_protocol>= 1.0.0 < 2.4.162.4.16
vmwarespring_advanced_message_queuing_protocol>= 3.0.0 < 3.0.93.0.9

CVSS provenance

nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.