Fedora Account System
Red Hat Associate
Red Hat Customer
In affected versions of Spring AMQP, a org.springframework.amqp.core.Message may be unsafely deserialized when being converted into a string. A malicious payload could be crafted to exploit this and enable a remote code execution attack. Upstream issue: https://jira.spring.io/browse/AMQP-766 Upstream patch: https://github.com/spring-projects/spring-amqp/commit/36e55998f6352ba3498be950ccab1d5f4d0ce655 References: https://pivotal.io/security/cve-2017-8045
Created springframework-amqp tracking bugs for this issue: Affects: fedora-all [bug 1493503]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.