3.8.1
8 years ago
11 months ago
Known vulnerabilities in the org.apache.james:james-server-spring package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
Affected versions of this package are vulnerable to Deserialization of Untrusted Data due to the exposure of a JMX endpoint on localhost that is subject to pre-authentication deserialization of untrusted data. An attacker can leverage a deserialization gadget as part of an exploit chain that could result in privilege escalation. Note: This is only exploitable if the JMX endpoint is bound locally and accessible to the attacker. How to fix Deserialization of Untrusted Data? Upgrade | [,3.7.5)[3.8.0,3.8.1) |