QID 997541
Date Published: 2024-02-28
QID 997541: Java (Maven) Security Update for org.apache.james:james-server (GHSA-px7w-c9gw-7gj3)
Apache James prior to version 3.7.5 and 3.8.0 exposes a JMX endpoint on localhost subject to pre-authentication deserialisation of untrusted data. Given a deserialisation gadjet, this could be leveraged as part of an exploit chain that could result in privilege escalation. Note that by default JMX endpoint is only bound locally.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-px7w-c9gw-7gj3 for updates and patch information.
Vendor References
- GHSA-px7w-c9gw-7gj3 -
github.com/advisories/GHSA-px7w-c9gw-7gj3
CVEs related to QID 997541
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-px7w-c9gw-7gj3 | org.apache.james:james-server |
|