https://seclists.org/oss-sec/2024/q1/161: CVE-2023-51518: Apache James server: Privilege escalation via JMX pre-authentication deserialisation
Published Feb 26, 2024
·Updated
Affected Software
1 affected component
Apache James Server<3.7.5, >=3.8<3.8.0
Frequently Asked Questions
1
What is the severity of CVE-2023-51518?
The severity of CVE-2023-51518 is classified as low.
2
Which versions of Apache James Server are affected by CVE-2023-51518?
CVE-2023-51518 affects Apache James Server versions prior to 3.7.5 and 3.8.0.
3
How do I fix CVE-2023-51518?
To fix CVE-2023-51518, upgrade to Apache James Server version 3.7.5 or later, or 3.8.0 or later.
4
What is the main issue described in CVE-2023-51518?
CVE-2023-51518 describes a privilege escalation vulnerability via JMX pre-authentication deserialization of untrusted data.
5
Is CVE-2023-51518 applicable to remote attacks?
CVE-2023-51518 is mainly a local issue since the JMX endpoint is exposed on localhost.