VDB
Sign up
HIGH7.8

GHSA-w7r6-v4j7-h94w

Apache James server's JMX management service vulnerable to privilege escalation by local user

Quick fix

GHSA-w7r6-v4j7-h94w — org.apache.james:javax-mail-extension: upgrade to the fixed version with the command below.

# pom.xml: bump <version>3.7.4</version> for org.apache.james:javax-mail-extension

Details

Apache James server version 3.7.3 and earlier provides a JMX management service without authentication by default. This allows privilege escalation by a malicious local user. Administrators are advised to disable JMX, or set up a JMX password. Note that version 3.7.4 onward will set up a JMX password automatically for Guice users.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.apache.james:javax-mail-extension
Introduced in: 0Fixed in: 3.7.4
Fix# pom.xml: bump <version>3.7.4</version> for org.apache.james:javax-mail-extension

References