DirectorySecurity Advisories
Sign In
Security Advisories

CGA-m894-hrqw-q27v

Published

Last updated

https://images.chainguard.dev/security/CGA-m894-hrqw-q27v
Package

keycloak

Latest Update
Not affected
Aliases
  • CVE-2021-38542
  • GHSA-84wg-rgp8-2hg4

Severity

5.9

Medium

CVSS V3

Summary

Command Injection in Apache James

Description

Apache James prior to release 3.6.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. This can result in Man-in -the-middle command injection attacks, leading potentially to leakage of sensible information.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images