Moderate severityNVD Advisory· Published Nov 30, 2021· Updated Aug 3, 2024
CVE-2021-22095
CVE-2021-22095
Description
In Spring AMQP versions 2.2.0 - 2.2.19 and 2.3.0 - 2.3.11, the Spring AMQP Message object, in its toString() method, will create a new String object from the message body, regardless of its size. This can cause an OOM Error with a large message
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.springframework.amqp:spring-amqpMaven | >= 2.2.0, < 2.2.20 | 2.2.20 |
org.springframework.amqp:spring-amqpMaven | >= 2.3.0, < 2.3.11 | 2.3.11 |
Affected products
2- Spring AMQP/Spring AMQPdescription
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-945q-ch46-pchgghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-22095ghsaADVISORY
- github.com/spring-projects/spring-amqp/commit/bde294d62a8b7f3f1d5a9f50f862c6f0782efb9dghsaWEB
- tanzu.vmware.com/security/cve-2021-22097ghsax_refsource_MISCWEB
News mentions
0No linked articles in our index yet.