Description
Apache James ManagedSieve implementation alongside with the file storage for sieve scripts is vulnerable to path traversal, allowing reading and writing any file. This vulnerability had been patched in Apache James 3.6.1 and higher. We recommend the upgrade. Distributed and Cassandra based products are also not impacted.
Remediation
References
https://www.openwall.com/lists/oss-security/2022/01/04/4
http://www.openwall.com/lists/oss-security/2022/01/04/4
http://www.openwall.com/lists/oss-security/2022/02/07/1
Related Vulnerabilities
CVE-2023-40341 Vulnerability in maven package io.jenkins.blueocean:blueocean
CVE-2018-15531 Vulnerability in maven package net.bull.javamelody:javamelody-core
CVE-2013-7370 Vulnerability in npm package connect
CVE-2021-42340 Vulnerability in maven package org.apache.tomcat:tomcat-websocket
CVE-2022-23496 Vulnerability in maven package nl.basjes.parse.useragent:yauaa-trino