CVE Database
/

CVE-2021-22097

Back to search

CVE-2021-22097

Published: Oct 28, 2021

Modified: Aug 3, 2024

PUBLISHED

Description

In Spring AMQP versions 2.2.0 - 2.2.18 and 2.3.0 - 2.3.10, the Spring AMQP Message object, in its toString() method, will deserialize a body for a message with content type application/x-java-serialized-object. It is possible to construct a malicious java.util.Dictionary object that can cause 100% CPU usage in the application if the toString() method is called.

VendorProductVersions

n/a

Spring AMQP

affected
Spring AMQP versions 2.2.X prior to 2.2.19 and 2.3.x prior to 2.3.11 .

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now