CVE-2023-34050MEDIUMCVSS 4.3≥ 1.0.0, < 2.4.17·≥ 3.0.0, < 3.0.102023-10-19
CVE-2023-34050 [MEDIUM] CWE-502 CVE-2023-34050:
In spring AMQP versions 1.0.0 to
2.4.16 and 3.0.0 to 3.0.9 , allowed list patterns for des
In spring AMQP versions 1.0.0 to
2.4.16 and 3.0.0 to 3.0.9 , allowed list patterns for deserializable class
names were added to Spring AMQP, allowing users to lock down deserialization of
data in messages from untrusted sources; however by default, when no allowed
list was provided, all classes could be deserialized.
Specifically, an application i
cvelistv5nvd