Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c38m-7h53-g9v4

Опубликовано: 21 янв. 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.1

Описание

Path traversal in Apache James

Apache James ManagedSieve implementation alongside with the file storage for sieve scripts is vulnerable to path traversal, allowing reading and writing any file. This vulnerability had been patched in Apache James 3.6.1 and higher. We recommend the upgrade. Distributed and Cassandra based products are also not impacted.

Пакеты

Наименование

org.apache.james:james-server

maven
Затронутые версииВерсия исправления

< 3.6.1

3.6.1

EPSS

Процентиль: 86%
0.02773
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 9.1
nvd
около 4 лет назад

Apache James ManagedSieve implementation alongside with the file storage for sieve scripts is vulnerable to path traversal, allowing reading and writing any file. This vulnerability had been patched in Apache James 3.6.1 and higher. We recommend the upgrade. Distributed and Cassandra based products are also not impacted.

EPSS

Процентиль: 86%
0.02773
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-22