[MAVEN:GHSA-C38M-7H53-G9V4] Path traversal in Apache James

Severity Critical
Affected Packages 1
Fixed Packages 1
CVEs 1

Apache James ManagedSieve implementation alongside with the file storage for sieve scripts is vulnerable to path traversal, allowing reading and writing any file. This vulnerability had been patched in Apache James 3.6.1 and higher. We recommend the upgrade. Distributed and Cassandra based products are also not impacted.

Package Affected Version
pkg:maven/org.apache.james/james-server < 3.6.1
Package Fixed Version
pkg:maven/org.apache.james/james-server = 3.6.1
ID
MAVEN:GHSA-C38M-7H53-G9V4
Severity
critical
URL
https://github.com/advisories/GHSA-c38m-7h53-g9v4
Published
2022-01-21T23:36:47
(2 years ago)
Modified
2023-02-03T05:04:11
(19 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.apache.james/james-server org.apache.james james-server < 3.6.1
Fixed pkg:maven/org.apache.james/james-server org.apache.james james-server = 3.6.1
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...