Description
Haraka version 2.8.8 and earlier comes with a plugin for processing attachments for zip files. Versions 2.8.8 and earlier can be vulnerable to command injection.
Remediation
References
https://github.com/outflanknl/Exploits/blob/master/harakiri-CVE-2016-1000282.py
Related Vulnerabilities
CVE-2016-0709 Vulnerability in maven package org.apache.portals.jetspeed-2:j2-admin
CVE-2023-36477 Vulnerability in maven package org.xwiki.platform:xwiki-platform-ckeditor-ui
CVE-2023-32314 Vulnerability in maven package org.webjars.npm:vm2
CVE-2022-29577 Vulnerability in maven package org.owasp.antisamy:antisamy
CVE-2023-48711 Vulnerability in npm package google-translate-api-browser