Spring Boot
cpe:2.3:a:pivotal_software:spring_boot:*:*:*:*:*:*:*, +1 more
- >= 4.0.0, <= 4.0.5
- >= 3.5.0, <= 3.5.13
A vulnerability exists in Spring Boot's RabbitMQ auto-configuration when an SSL bundle is used. The issue arises because hostname verification is not performed when connecting to the RabbitMQ broker. This vulnerability affects Spring Boot versions 4.0.0 to 4.0.5 and 3.5.0 to 3.5.13.
The lack of hostname verification can lead to man-in-the-middle attacks, where an attacker could intercept and potentially alter the communication between the Spring Boot application and the RabbitMQ broker.
Users should upgrade to Spring Boot 4.0.6 or 3.5.14, depending on their current version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.