cve/2023/CVE-2023-26269.md
2024-05-25 21:48:12 +02:00

895 B

CVE-2023-26269

Description

Apache James server version 3.7.3 and earlier provides a JMX management service without authentication by default. This allows privilege escalation by a malicious local user.Administrators are advised to disable JMX, or set up a JMX password.Note that version 3.7.4 onward will set up a JMX password automatically for Guice users.

POC

Reference

No PoCs from references.

Github