-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability manifests in file-based user repository implementations during user creation. While no patch diffs are available, the CWE-78 classification and Apache's mitigation advice indicate: 1) User input flows into OS command execution 2) File-based repositories are specifically implicated. The UsersFileRepository and its parent AbstractUsersRepository are the core components handling user management in this configuration. The medium confidence reflects educated inference based on vulnerability type and component architecture without direct patch evidence.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.apache.james:james-server | maven | < 2.3.2.1 | 2.3.2.1 |
Ongoing coverage of React2Shell