ZeroHour

CVE-2018-11087

CVSS 3.1
5.9 medium
EPSS
1%p68
Published
()
Modified
Description

Pivotal Spring AMQP, 1.x versions prior to 1.7.10 and 2.x versions prior to 2.0.6, expose a man-in-the-middle vulnerability due to lack of hostname validation. A malicious user that has the ability to intercept traffic would be able to view data in transit.

Vendors
pivotal softwarevmware
Products
spring advanced message queuing protocol, rabbitmq java client
Weakness
CWE-295
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.