Medium severity5.9NVD Advisory· Published Sep 14, 2018· Updated Jun 17, 2026
CVE-2018-11087
CVE-2018-11087
Description
Pivotal Spring AMQP, 1.x versions prior to 1.7.10 and 2.x versions prior to 2.0.6, expose a man-in-the-middle vulnerability due to lack of hostname validation. A malicious user that has the ability to intercept traffic would be able to view data in transit.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.springframework.amqp:spring-amqpMaven | >= 2.0.0, < 2.0.6 | 2.0.6 |
org.springframework.amqp:spring-amqpMaven | < 1.7.10 | 1.7.10 |
com.rabbitmq:amqp-clientMaven | < 4.8.0 | 4.8.0 |
com.rabbitmq:amqp-clientMaven | >= 5.0.0, < 5.4.0 | 5.4.0 |
Affected products
3- ghsa-coords2 versions
< 4.8.0+ 1 more
- (no CPE)range: < 4.8.0
- (no CPE)range: >= 2.0.0, < 2.0.6
- Pivotal/Spring AMQPv5Range: 1.x
Patches
Vulnerability mechanics
References
3- github.com/advisories/GHSA-w4g2-9hj6-5472ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2018-11087ghsaADVISORY
- pivotal.io/security/cve-2018-11087nvdMitigationVendor AdvisoryWEB
News mentions
0No linked articles in our index yet.