CVE-2020-36282
CRITICALRabbitmq Jms Client < 1.15.2 - Insecure Deserialization
Title source: ruleDescription
JMS Client for RabbitMQ 1.x before 1.15.2 and 2.x before 2.2.0 is vulnerable to unsafe deserialization that can result in code execution via crafted StreamMessage data.
References (4)
Scores
CVSS v3
9.8
EPSS
0.0170
EPSS Percentile
82.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-502
Status
published
Affected Products (2)
rabbitmq/jms_client
< 1.15.2
com.rabbitmq.jms/rabbitmq-jms
< 2.2.0Maven
Timeline
Published
Mar 12, 2021
Tracked Since
Feb 18, 2026