VDB

CVE-2021-22097

CVE-2021-22097 PUBLISHED CVSS 6.800000190734863 MEDIUM

In Spring AMQP versions 2.2.0 - 2.2.18 and 2.3.0 - 2.3.10, the Spring AMQP Message object, in its toString() method, will deserialize a body for a message with content type application/x-java-serialized-object. It is possible to construct a malicious java.util.Dictionary object that can cause 100% CPU usage in the application if the toString() method is called.

EPSS 1.04% · 60.7th percentile

Risk Scores

CVSS 2.0
6.800000190734863
EPSS Score
1.04%
60.7th percentile

Affected Products

VendorProductVersions
Mavenorg.springframework.amqp:spring-amqp2.2.0, 2.3.0
vmwarespring_advanced_message_queuing_protocol2.3.0, 2.2.0
n/aSpring AMQP*

Timeline

  • Oct 28, 2021 CVE Published
  • Oct 29, 2021 EPSS Score
  • Nov 1, 2021 CVE Updated
  • Dec 24, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 18, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • Apr 15, 2022 EPSS Score
  • Jun 10, 2022 EPSS Score
  • Aug 6, 2022 EPSS Score
  • Oct 1, 2022 EPSS Score
  • Jan 21, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›