GHSA-xj7q-q94c-6wr3
Dashboard / Vulnerabilities / GHSA-xj7q-q94c-6wr3
Summary: Apache James Privilege Escalation
Details: The JMX server embedded in Apache James, also used by the command line client is exposed to a java de-serialization issue, and thus can be used to execute arbitrary commands. As James exposes JMX socket by default only on local-host, this vulnerability can only be used for privilege escalation. Release 3.0.1 upgrades the incriminated library.
References: https://nvd.nist.gov/vuln/detail/CVE-2017-12628, https://github.com/apache/james-project, https://web.archive.org/web/20210124113233/http://www.securityfocus.com/bid/101532, https://www.mail-archive.com/[email protected]/msg15633.html
Affected packages
Package
Name: org.apache.james:james-project
Purl: pkg:maven/org.apache.james/james-project
Affected ranges
Type: ECOSYSTEM
Events:
