CVE-2017-8045

Source
https://cve.org/CVERecord?id=CVE-2017-8045
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-8045.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2017-8045
Aliases
Published
2017-11-27T10:29:00.907Z
Modified
2026-07-08T11:36:28.087005Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

In Pivotal Spring AMQP versions prior to 1.7.4, 1.6.11, and 1.5.7, an org.springframework.amqp.core.Message may be unsafely deserialized when being converted into a string. A malicious payload could be crafted to exploit this and enable a remote code execution attack.

References

Affected packages

Git / github.com/spring-projects/spring-amqp

Affected ranges

Type
GIT
Repo
https://github.com/spring-projects/spring-amqp
Events
Database specific
Show details
{
    "cpe": [
        "cpe:2.3:a:pivotal_software:spring_advanced_message_queuing_protocol:1.5.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:pivotal_software:spring_advanced_message_queuing_protocol:1.5.0:m1:*:*:*:*:*:*",
        "cpe:2.3:a:pivotal_software:spring_advanced_message_queuing_protocol:1.5.0:rc1:*:*:*:*:*:*",
        "cpe:2.3:a:pivotal_software:spring_advanced_message_queuing_protocol:1.5.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:pivotal_software:spring_advanced_message_queuing_protocol:1.5.2:*:*:*:*:*:*:*",
        "cpe:2.3:a:pivotal_software:spring_advanced_message_queuing_protocol:1.5.3:*:*:*:*:*:*:*",
        "cpe:2.3:a:pivotal_software:spring_advanced_message_queuing_protocol:1.5.4:*:*:*:*:*:*:*",
        "cpe:2.3:a:pivotal_software:spring_advanced_message_queuing_protocol:1.5.5:*:*:*:*:*:*:*",
        "cpe:2.3:a:pivotal_software:spring_advanced_message_queuing_protocol:1.5.6:*:*:*:*:*:*:*",
        "cpe:2.3:a:pivotal_software:spring_advanced_message_queuing_protocol:1.6.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:pivotal_software:spring_advanced_message_queuing_protocol:1.6.0:m1:*:*:*:*:*:*",
        "cpe:2.3:a:pivotal_software:spring_advanced_message_queuing_protocol:1.6.0:m2:*:*:*:*:*:*",
        "cpe:2.3:a:pivotal_software:spring_advanced_message_queuing_protocol:1.6.0:rc1:*:*:*:*:*:*",
        "cpe:2.3:a:pivotal_software:spring_advanced_message_queuing_protocol:1.6.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:pivotal_software:spring_advanced_message_queuing_protocol:1.6.2:*:*:*:*:*:*:*",
        "cpe:2.3:a:pivotal_software:spring_advanced_message_queuing_protocol:1.6.3:*:*:*:*:*:*:*",
        "cpe:2.3:a:pivotal_software:spring_advanced_message_queuing_protocol:1.6.4:*:*:*:*:*:*:*",
        "cpe:2.3:a:pivotal_software:spring_advanced_message_queuing_protocol:1.6.5:*:*:*:*:*:*:*",
        "cpe:2.3:a:pivotal_software:spring_advanced_message_queuing_protocol:1.6.6:*:*:*:*:*:*:*",
        "cpe:2.3:a:pivotal_software:spring_advanced_message_queuing_protocol:1.6.7:*:*:*:*:*:*:*",
        "cpe:2.3:a:pivotal_software:spring_advanced_message_queuing_protocol:1.6.8:*:*:*:*:*:*:*",
        "cpe:2.3:a:pivotal_software:spring_advanced_message_queuing_protocol:1.6.9:*:*:*:*:*:*:*",
        "cpe:2.3:a:pivotal_software:spring_advanced_message_queuing_protocol:1.6.10:*:*:*:*:*:*:*",
        "cpe:2.3:a:pivotal_software:spring_advanced_message_queuing_protocol:1.7.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:pivotal_software:spring_advanced_message_queuing_protocol:1.7.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:pivotal_software:spring_advanced_message_queuing_protocol:1.7.2:*:*:*:*:*:*:*",
        "cpe:2.3:a:pivotal_software:spring_advanced_message_queuing_protocol:1.7.3:*:*:*:*:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "1.5.0"
        },
        {
            "last_affected": "1.5.0"
        },
        {
            "introduced": "1.5.0-m1"
        },
        {
            "last_affected": "1.5.0-m1"
        },
        {
            "introduced": "1.5.0-rc1"
        },
        {
            "last_affected": "1.5.0-rc1"
        },
        {
            "introduced": "1.5.1"
        },
        {
            "last_affected": "1.5.1"
        },
        {
            "introduced": "1.5.2"
        },
        {
            "last_affected": "1.5.2"
        },
        {
            "introduced": "1.5.3"
        },
        {
            "last_affected": "1.5.3"
        },
        {
            "introduced": "1.5.4"
        },
        {
            "last_affected": "1.5.4"
        },
        {
            "introduced": "1.5.5"
        },
        {
            "last_affected": "1.5.5"
        },
        {
            "introduced": "1.5.6"
        },
        {
            "last_affected": "1.5.6"
        },
        {
            "introduced": "1.6.0"
        },
        {
            "last_affected": "1.6.0"
        },
        {
            "introduced": "1.6.0-m1"
        },
        {
            "last_affected": "1.6.0-m1"
        },
        {
            "introduced": "1.6.0-m2"
        },
        {
            "last_affected": "1.6.0-m2"
        },
        {
            "introduced": "1.6.0-rc1"
        },
        {
            "last_affected": "1.6.0-rc1"
        },
        {
            "introduced": "1.6.1"
        },
        {
            "last_affected": "1.6.1"
        },
        {
            "introduced": "1.6.2"
        },
        {
            "last_affected": "1.6.2"
        },
        {
            "introduced": "1.6.3"
        },
        {
            "last_affected": "1.6.3"
        },
        {
            "introduced": "1.6.4"
        },
        {
            "last_affected": "1.6.4"
        },
        {
            "introduced": "1.6.5"
        },
        {
            "last_affected": "1.6.5"
        },
        {
            "introduced": "1.6.6"
        },
        {
            "last_affected": "1.6.6"
        },
        {
            "introduced": "1.6.7"
        },
        {
            "last_affected": "1.6.7"
        },
        {
            "introduced": "1.6.8"
        },
        {
            "last_affected": "1.6.8"
        },
        {
            "introduced": "1.6.9"
        },
        {
            "last_affected": "1.6.9"
        },
        {
            "introduced": "1.6.10"
        },
        {
            "last_affected": "1.6.10"
        },
        {
            "introduced": "1.7.0"
        },
        {
            "last_affected": "1.7.0"
        },
        {
            "introduced": "1.7.1"
        },
        {
            "last_affected": "1.7.1"
        },
        {
            "introduced": "1.7.2"
        },
        {
            "last_affected": "1.7.2"
        },
        {
            "introduced": "1.7.3"
        },
        {
            "last_affected": "1.7.3"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

1.*
1.5.0
1.5.0-m1
1.5.0-rc1
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.6.0
1.6.0-m1
1.6.0-m2
1.6.0-rc1
1.6.1
1.6.10
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
v1.*
v1.5.0.RELEASE
v1.5.1.RELEASE
v1.5.2.RELEASE
v1.6.0.M1
v1.6.0.M2
v1.6.0.RC1
v1.6.0.RELEASE
v1.6.1.RELEASE
v1.6.2.RELEASE
v1.6.3.RELEASE
v1.6.4.RELEASE
v1.6.5.RELEASE
v1.7.0.RC1
v1.7.0.RELEASE
v1.7.1.RELEASE
v1.7.2.RELEASE
v1.7.3.RELEASE

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-8045.json"