In Spring AMQP versions 2.2.0 - 2.2.18 and 2.3.0 - 2.3.10, the Spring AMQP Message object, in its toString() method, will deserialize a body for a message with content type application/x-java-serialized-object. It is possible to construct a malicious java.util.Dictionary object that can cause 100% CPU usage in the application if the toString() method is called.
{
"cpe": "cpe:2.3:a:vmware:spring_advanced_message_queuing_protocol:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "2.2.0"
},
{
"last_affected": "2.2.18"
},
{
"introduced": "2.3.0"
},
{
"last_affected": "2.3.10"
}
],
"source": "CPE_RANGE"
}