Description
Pivotal Spring AMQP, 1.x versions prior to 1.7.10 and 2.x versions prior to 2.0.6, expose a man-in-the-middle vulnerability due to lack of hostname validation. A malicious user that has the ability to intercept traffic would be able to view data in transit.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-0705 | Pivotal Spring AMQP, 1.x versions prior to 1.7.10 and 2.x versions prior to 2.0.6, expose a man-in-the-middle vulnerability due to lack of hostname validation. A malicious user that has the ability to intercept traffic would be able to view data in transit. |
Github GHSA |
GHSA-w4g2-9hj6-5472 | Moderate severity vulnerability that affects com.rabbitmq:amqp-client and org.springframework.amqp:spring-amqp |
References
| Link | Providers |
|---|---|
| https://pivotal.io/security/cve-2018-11087 |
|
History
Thu, 27 Mar 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vmware
Vmware rabbitmq Java Client |
|
| CPEs | cpe:2.3:a:vmware:rabbitmq_java_client:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Pivotal Software rabbitmq
|
Vmware
Vmware rabbitmq Java Client |
| Metrics |
cvssV3_0
|
cvssV3_1
|
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2024-09-17T03:58:41.663Z
Reserved: 2018-05-14T00:00:00.000Z
Link: CVE-2018-11087
No data.
Status : Analyzed
Published: 2018-09-14T20:29:00.417
Modified: 2025-03-27T19:56:20.387
Link: CVE-2018-11087
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA