CVE-2016-2173: Fedoraproject Fedora
Critical severity, CVSS 9.8. EPSS: 6.3% chance of exploitation in the next 30 days.
org.springframework.core.serializer.DefaultDeserializer in Spring AMQP before 1.5.5 allows remote attackers to execute arbitrary code.
Affected products
- Fedoraproject Fedora: version 22 only; version 23 only; version 24 only
- VMware Spring Advanced Message Queuing Protocol: before 1.5.5 (fixed in 1.5.5)
Published 2017-04-21. Last modified 2026-06-17.