CVE-2018-11087: Pivotal Software Spring Advanced Message Queuing Protocol
Medium severity, CVSS 5.9. EPSS: 1.2% chance of exploitation in the next 30 days.
Pivotal Spring AMQP, 1.x versions prior to 1.7.10 and 2.x versions prior to 2.0.6, expose a man-in-the-middle vulnerability due to lack of hostname validation. A malicious user that has the ability to intercept traffic would be able to view data in transit.
Affected products
- Pivotal Software Spring Advanced Message Queuing Protocol: from 1.0.0, before 1.7.10 (fixed in 1.7.10); from 2.0.0, before 2.0.6 (fixed in 2.0.6)
- VMware Rabbitmq Java Client: before 4.8.0 (fixed in 4.8.0); from 4.8.1, before 5.4.0 (fixed in 5.4.0)
Published 2018-09-14. Last modified 2026-06-17.