6.8
CVE-2026-59272
- EPSS 0.16%
- Veröffentlicht 27.08.2026 16:41:08
- Zuletzt bearbeitet 01.09.2026 15:50:45
- Erkennungen
Log4j2 AmqpAppender disables TLS hostname verification by default
Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of every log event. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMware ≫ Spring Advanced Message Queuing Protocol Version < 2.4.19
VMware ≫ Spring Advanced Message Queuing Protocol Version >= 3.2.0 < 3.2.13
VMware ≫ Spring Advanced Message Queuing Protocol Version >= 4.0.0 < 4.0.4.1
VMware ≫ Spring Advanced Message Queuing Protocol Version >= 4.1.0 < 4.1.0.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.058 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| VMware | 6.8 | 1.6 | 5.2 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
|
CWE-297 Improper Validation of Certificate with Host Mismatch
The product communicates with a host that provides a certificate, but the product does not properly ensure that the certificate is actually associated with that host.
https://spring.io/security/cve-2026-59272