com.rabbitmq:amqp-client@5.10.0 vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the com.rabbitmq:amqp-client package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Resource Exhaustion

Affected versions of this package are vulnerable to Resource Exhaustion in DirectMessageListenerContainer.java, which does not use maxBodyLebgth. An attacker can cause a memory overflow and trigger an Out Of Memory error by sending a very large Message object.

How to fix Resource Exhaustion?

Upgrade com.rabbitmq:amqp-client to version 5.14.3, 5.16.1, 5.17.1 or higher.

[,5.14.3) [5.15.0,5.16.1) [5.17.0,5.17.1)