CVE-2017-8045: Pivotal Software Spring Advanced Message Queuing Protocol

Critical severity, CVSS 9.8. EPSS: 3.6% chance of exploitation in the next 30 days.

In Pivotal Spring AMQP versions prior to 1.7.4, 1.6.11, and 1.5.7, an org.springframework.amqp.core.Message may be unsafely deserialized when being converted into a string. A malicious payload could be crafted to exploit this and enable a remote code execution attack.

Affected products

  • Pivotal Software Spring Advanced Message Queuing Protocol: version 1.5.0 only; version 1.5.1 only; version 1.5.2 only; version 1.5.3 only; version 1.5.4 only; version 1.5.5 only; …

Published 2017-11-27. Last modified 2026-06-17.