MEDIUM5.9
GHSA-84wg-rgp8-2hg4
Command Injection in Apache James
Quick fix
GHSA-84wg-rgp8-2hg4 — org.apache.james:james-server: upgrade to the fixed version with the command below.
# pom.xml: bump <version>3.6.1</version> for org.apache.james:james-serverDetails
Apache James prior to release 3.6.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. This can result in Man-in -the-middle command injection attacks, leading potentially to leakage of sensible information.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.apache.james:james-server
Introduced in:
0Fixed in: 3.6.1Fix
# pom.xml: bump <version>3.6.1</version> for org.apache.james:james-server