Spring AMQP是将核心 Spring 概念应用于基于 AMQP 的消息传递解决方案的开发。 Spring AMQP 1.0.0 到2.4.16 、 3.0.0 到 3.0.9版本存在安全漏洞,该漏洞源于Spring AMQP 中添加了可反序列化类名的允许列表模式,允许用户锁定来自不受信任来源的消息中数据的反序列化。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Spring | Spring AMQP | 1.0.0 ~ 2.4.17 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | A Proof of Concept of Spring AMQP Deserialization Vulnerability (CVE-2023-34050) | https://github.com/X1r0z/spring-amqp-deserialization | POC Details |
No public POC found.
Login to generate AI POCNo comments yet