CVE-2017-8045

critical
Published 2017-11-27 · Modified 2023-11-08
CVSS v3
9.8
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
7.5
VIR risk
9.8

Description

Deserialization of Untrusted Data in Spring AMQP

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: security_alert@emc.com — https://pivotal.io/security/cve-2017-8045

Package impact

EcosystemPackageVulnerableFixed
java Mavenorg.springframework.amqp:spring-amqp<1.5.71.5.7
java Mavenorg.springframework.amqp:spring-amqp>=1.6.0,<1.6.111.6.11
java Mavenorg.springframework.amqp:spring-amqp>=1.7.0,<1.7.41.7.4

Application impact

VendorProductVersionsFixed
pivotal_softwarespring_advanced_message_queuing_protocol1.5.0
pivotal_softwarespring_advanced_message_queuing_protocol1.5.1
pivotal_softwarespring_advanced_message_queuing_protocol1.5.2
pivotal_softwarespring_advanced_message_queuing_protocol1.5.3
pivotal_softwarespring_advanced_message_queuing_protocol1.5.4
pivotal_softwarespring_advanced_message_queuing_protocol1.5.5
pivotal_softwarespring_advanced_message_queuing_protocol1.5.6
pivotal_softwarespring_advanced_message_queuing_protocol1.6.0
pivotal_softwarespring_advanced_message_queuing_protocol1.6.1
pivotal_softwarespring_advanced_message_queuing_protocol1.6.2
pivotal_softwarespring_advanced_message_queuing_protocol1.6.3
pivotal_softwarespring_advanced_message_queuing_protocol1.6.4
pivotal_softwarespring_advanced_message_queuing_protocol1.6.5
pivotal_softwarespring_advanced_message_queuing_protocol1.6.6
pivotal_softwarespring_advanced_message_queuing_protocol1.6.7
pivotal_softwarespring_advanced_message_queuing_protocol1.6.8
pivotal_softwarespring_advanced_message_queuing_protocol1.6.9
pivotal_softwarespring_advanced_message_queuing_protocol1.6.10
pivotal_softwarespring_advanced_message_queuing_protocol1.7.0
pivotal_softwarespring_advanced_message_queuing_protocol1.7.1
pivotal_softwarespring_advanced_message_queuing_protocol1.7.2
pivotal_softwarespring_advanced_message_queuing_protocol1.7.3

References

CWEs

CWE-502

Verify integrity in audit chain (admin only). AS-IS.