Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreIn affected versions of Spring AMQP, a org.springframework.amqp.core.Message
may be unsafely deserialized when being converted into a string. A malicious payload could be crafted to exploit this and enable a remote code execution attack.
Users of affected versions should apply the following mitigation:
This vulnerability was responsibly reported by Man Yue Mo from Semmle and lgtm.com.
2017-09-19: Initial vulnerability report published
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy