AsyncAPI is an open-specification project for defining event-driven and asynchronous APIs, with disclosed vulnerabilities concentrating in Spring Cloud Stream template implementations that generate or process message-broker configurations. The observed exposure recurs through code-injection weaknesses arising from improper control of dynamic code generation in these template-based frameworks. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Asyncapi over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-37694HIGH @asyncapi/java-spring-cloud-stream-template generates a Spring Cloud Stream (SCSt) microservice. In versions prior to 0.7.0 arbitrary code injection was possible when an attacker c | Aug 11, 2021 | 7.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Asyncapi.
Media articles that mention a CVE ID that affects a product developed by Asyncapi — matched by CVE ID, not by vendor name.