Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-41701

Опубликовано: 09 июн. 2026
Источник: redhat
CVSS3: 4.4
EPSS Низкий

Описание

Correlation IDs for replies in the RabbitTemplate.sendAndReceive() with the fixed reply queue are predictable due to internal simple counter. Affected versions: Spring AMQP 4.0.0 through 4.0.3; 3.2.0 through 3.2.10; 3.1.0 through 3.1.15; 2.4.0 through 2.4.17.

A flaw was found in Spring AMQP. The system generates predictable correlation identifiers (IDs) for message replies due to an internal simple counter. This predictability could allow an attacker to potentially infer or manipulate message flows, leading to a low impact on the confidentiality and integrity of data.

Отчет

Red Hat products that bundle Spring AMQP are affected by this flaw. However, exploitation requires the application to use fixed reply queues rather than exclusive/auto-delete queues, and the attacker needs high privileges and network access to the RabbitMQ broker, significantly limiting practical exploitability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apache Camel 4 for Quarkus 3spring-amqpFix deferred
Red Hat Fuse 7spring-amqpOut of support scope
Red Hat JBoss Enterprise Application Platform Expansion Packspring-amqpFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-342
https://bugzilla.redhat.com/show_bug.cgi?id=2487399Spring AMQP: Spring AMQP: Predictable correlation IDs may lead to information disclosure

EPSS

Процентиль: 7%
0.00173
Низкий

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.4
nvd
2 месяца назад

Correlation IDs for replies in the RabbitTemplate.sendAndReceive() with the fixed reply queue are predictable due to internal simple counter. Affected versions: Spring AMQP 4.0.0 through 4.0.3; 3.2.0 through 3.2.10; 3.1.0 through 3.1.15; 2.4.0 through 2.4.17.

CVSS3: 4.4
github
2 месяца назад

Correlation IDs for replies in the RabbitTemplate.sendAndReceive() with the fixed reply queue are predictable due to internal simple counter. Affected versions: Spring AMQP 4.0.0 through 4.0.3; 3.2.0 through 3.2.10; 3.1.0 through 3.1.15; 2.4.0 through 2.4.17.

EPSS

Процентиль: 7%
0.00173
Низкий

4.4 Medium

CVSS3