CyberRota Analysis
AI-GeneratedApplications using Log4j2 to send logs to RabbitMQ over TLS with default settings are vulnerable to man-in-the-middle attacks, allowing an attacker to intercept all log events. This vulnerability affects specific versions of Spring AMQP, making it critical for developers and organizations utilizing these versions to prioritize remediation efforts to secure their logging processes. Immediate action is recommended to mitigate potential data exposure risks.
Original NVD Description
Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of every log event. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier
Related CVEs
Other vulnerabilities affecting the same vendor(s)