Medium · published August 27, 2026
Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of every log event.
Spring AMQP 4.1.0
Spring AMQP 4.0.0 - 4.0.4
Spring AMQP 3.2.0 - 3.2.12
Spring AMQP 2.4.18 and earlier
| Product | Versions | Fixed in |
|---|---|---|
| vmware/spring_advanced_message_queuing_protocol | < 2.4.19 | 2.4.19 |
| vmware/spring_advanced_message_queuing_protocol | ≥ 3.2.0, < 3.2.13 | 3.2.13 |
| vmware/spring_advanced_message_queuing_protocol | ≥ 4.0.0, < 4.0.4.1 | 4.0.4.1 |
| vmware/spring_advanced_message_queuing_protocol | ≥ 4.1.0, < 4.1.0.1 | 4.1.0.1 |