Overview
About vulnerability
Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of every log event. Attackers on the network path can read or alter log traffic (often containing tokens, PII, or stack traces with secrets) without certificate errors. The docs promise hostname verification is on by default, so operators have no reason to suspect exposure.Details
- Affected product:
- Spring
- Affected packages:
- Spring Integration @ 5.5.19 (+1741 more)