spring-rabbit is vulnerable to Improper Validation of Certificate with Host Mismatch
68
Medium Risk
spring-rabbit Log4j2 AmqpAppender disables TLS hostname verification by default even though the documentation says it is on. An on-path attacker can intercept log traffic that often contains tokens, PII, or secrets in stack traces. Operators have no configuration signal that verification is off. The patch enables hostname verification by default.
You are affected if you are using a version that falls within the vulnerable range and logs are shipped to RabbitMQ over TLS with the Log4j2 AmqpAppender using default hostname verification.
spring-rabbit is vulnerable to Improper Validation of Certificate with Host Mismatch in versions 0.0.1 - 4.0.4 and 4.1.0 - 4.1.0.
Upgrade the org.springframework.amqp:spring-rabbit library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant