Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:6054
HistoryApr 06, 2018 - 1:07 a.m.

Remote Code Execution (RCE)

2018-04-0601:07:42
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

0.793 High

EPSS

Percentile

98.3%

spring-messaging is susceptible to remote code execution (RCE) attack. The vulnerability exists through the simple STOMP broker that exposes a weakness to malicious users who can perform a RCE attack through the STORM payload.

References