Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xj7q-q94c-6wr3

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.8

Описание

Apache James Privilege Escalation

The JMX server embedded in Apache James, also used by the command line client is exposed to a java de-serialization issue, and thus can be used to execute arbitrary commands. As James exposes JMX socket by default only on local-host, this vulnerability can only be used for privilege escalation. Release 3.0.1 upgrades the incriminated library.

Пакеты

Наименование

org.apache.james:james-project

maven
Затронутые версииВерсия исправления

< 3.0.1

3.0.1

EPSS

Процентиль: 35%
0.00142
Низкий

7.8 High

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 7.8
nvd
больше 8 лет назад

The JMX server embedded in Apache James, also used by the command line client is exposed to a java de-serialization issue, and thus can be used to execute arbitrary commands. As James exposes JMX socket by default only on local-host, this vulnerability can only be used for privilege escalation. Release 3.0.1 upgrades the incriminated library.

EPSS

Процентиль: 35%
0.00142
Низкий

7.8 High

CVSS3

Дефекты

CWE-502