QID 994952
Date Published: 2023-08-22
QID 994952: Java (Maven) Security Update for org.apache.james:james-project (GHSA-xj7q-q94c-6wr3)
The JMX server embedded in Apache James, also used by the command line client is exposed to a java de-serialization issue, and thus can be used to execute arbitrary commands. As James exposes JMX socket by default only on local-host, this vulnerability can only be used for privilege escalation. Release 3.0.1 upgrades the incriminated library.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-xj7q-q94c-6wr3 for updates and patch information.
Vendor References
- GHSA-xj7q-q94c-6wr3 -
github.com/advisories/GHSA-xj7q-q94c-6wr3
CVEs related to QID 994952
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-xj7q-q94c-6wr3 | org.apache.james:james-project |
|