GHSA-xj7q-q94c-6wr3
HIGHCVE-2017-12628The JMX server embedded in Apache James, also used by the command line client is exposed to a java de-serialization issue, and thus can be used to execute arbitrary commands. As James exposes JMX socket by default only on local-host, this vulnerability can only be used for privilege escalation. Release 3.0.1 upgrades the incriminated library.
- Affected
- < 3.0.1
- Fixed in
- 3.0.1
- Published
- 2022-05-17
- Source
- github