HIGH7.8
GHSA-w7r6-v4j7-h94w
Apache James server's JMX management service vulnerable to privilege escalation by local user
Quick fix
GHSA-w7r6-v4j7-h94w — org.apache.james:javax-mail-extension: upgrade to the fixed version with the command below.
# pom.xml: bump <version>3.7.4</version> for org.apache.james:javax-mail-extensionDetails
Apache James server version 3.7.3 and earlier provides a JMX management service without authentication by default. This allows privilege escalation by a malicious local user. Administrators are advised to disable JMX, or set up a JMX password. Note that version 3.7.4 onward will set up a JMX password automatically for Guice users.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.apache.james:javax-mail-extension
Introduced in:
0Fixed in: 3.7.4Fix
# pom.xml: bump <version>3.7.4</version> for org.apache.james:javax-mail-extension