In spring AMQP versions 1.0.0 to 2.4.16 and 3.0.0 to 3.0.9 , allowed list patterns for deserializable class names were added to Spring AMQP, allowing users to lock down deserialization of data in messages from untrusted sources; however by default, when no allowed list was provided, all classes could be deserialized.
Specifically, an application is vulnerable if
the SimpleMessageConverter or SerializerMessageConverter is used
the user does not configure allowed list patterns
untrusted message originators gain permissions to write messages to the RabbitMQ broker to send malicious content
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a Proof of Concept (PoC) for CVE-2023-34050, a deserialization vulnerability in Spring AMQP. The project is structured as a multi-module Maven project with separate 'client' and 'server' components. The 'client' module constructs a malicious serialized Java object using gadget chains (TemplatesImpl, POJONode, BadAttributeValueExpException) and sends it to a RabbitMQ exchange ('test_exchange') using the Spring AMQP RabbitTemplate. The payload is designed to execute an arbitrary system command (e.g., 'open -a Calculator') on the target server upon deserialization. The 'server' module listens to a RabbitMQ queue ('test_queue') and prints received messages, simulating a vulnerable application. Configuration files specify the RabbitMQ broker at 127.0.0.1:5672. The exploit demonstrates remote code execution via AMQP message deserialization in affected Spring AMQP versions. The code is a functional PoC and does not include detection logic or fake elements.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.