3.9.0
9 years ago
1 months ago
Known vulnerabilities in the org.apache.james:james-server-spring package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
Affected versions of this package are vulnerable to Deserialization of Untrusted Data due to the exposure of a JMX endpoint on localhost that is subject to pre-authentication deserialization of untrusted data. An attacker can leverage a deserialization gadget as part of an exploit chain that could result in privilege escalation. Note: This is only exploitable if the JMX endpoint is bound locally and accessible to the attacker. How to fix Deserialization of Untrusted Data? Upgrade | [,3.7.5)[3.8.0,3.8.1) |