JMS Client for RabbitMQ 1.x before 1.15.2 and 2.x before 2.2.0 is vulnerable to unsafe deserialization that can result in code execution via crafted StreamMessage data.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| com.rabbitmq.jms:rabbitmq-jms(Maven) | 2.0 | 2.2.0 | N/A |
| com.rabbitmq.jms:rabbitmq-jms(Maven) | 1.0 | 1.15.2 | N/A |
CVSS Metrics