CVE-2021-22095

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
30/11/2021
Last modified:
01/12/2021

Description

In Spring AMQP versions 2.2.0 - 2.2.19 and 2.3.0 - 2.3.11, the Spring AMQP Message object, in its toString() method, will create a new String object from the message body, regardless of its size. This can cause an OOM Error with a large message

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vmware:spring_advanced_message_queuing_protocol:*:*:*:*:*:*:*:* 2.2.0 (including) 2.2.19 (excluding)
cpe:2.3:a:vmware:spring_advanced_message_queuing_protocol:*:*:*:*:*:*:*:* 2.3.0 (including) 2.3.11 (excluding)


References to Advisories, Solutions, and Tools