Spring AMQP是将核心 Spring 概念应用于基于 AMQP 的消息传递解决方案的开发。 Spring AMQP 2.2.0 - 2.2.19和2.3.0 - 2.3.11版本存在安全漏洞,该漏洞源于Spring AMQP Message对象在其toString()方法中,将从消息体中创建一个新的String对象,缺少对对象的大小的限制与过滤。这可能会导致带有超大消息的OOM错误。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | Spring AMQP | Spring AMQP versions 2.2.X prior to 2.2.20 and 2.3.x prior to 2.3.12 . | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-43284 | Victure WR1200信任管理问题漏洞 | |
| CVE-2021-40101 | PortlandLabs Concrete CMS 安全漏洞 | |
| CVE-2021-42564 | Cryptshare Ag Cryptshare 输入验证错误漏洞 | |
| CVE-2021-31787 | Actions ATS2815 输入验证错误漏洞 | |
| CVE-2021-42099 | Zoho ManageEngine M365 Manager Plus 4421 代码问题漏洞 | |
| CVE-2021-43319 | Zoho Corporation Zoho ManageEngine Network Configuration Manager 命令注入漏洞 | |
| CVE-2021-43296 | Zoho ManageEngine SupportCenter Plus 代码问题漏洞 | |
| CVE-2021-43295 | Zoho ManageEngine SupportCenter Plus 跨站脚本漏洞 | |
| CVE-2021-43294 | Zoho ManageEngine SupportCenter Plus 跨站脚本漏洞 | |
| CVE-2021-41677 | Open Solutions For Education openSIS SQL注入漏洞 | |
| CVE-2021-43283 | Victure WR1200 操作系统命令注入漏洞 | |
| CVE-2021-43282 | Victure WR1200 信任管理问题漏洞 | |
| CVE-2021-44230 | PortSwigger Burp Suite 访问控制错误漏洞 | |
| CVE-2021-43202 | Jetbrains JetBrains TeamCity 访问控制错误漏洞 | |
| CVE-2021-43998 | HashiCorp Vault 安全漏洞 | |
| CVE-2021-41679 | Open Solutions For Education openSIS SQL注入漏洞 | |
| CVE-2021-41678 | Open Solutions For Education openSIS SQL注入漏洞 |
No comments yet