Critical severity vulnerability that affects Haraka
Critical severity
GitHub Reviewed
Published
Feb 12, 2019
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Published to the GitHub Advisory Database
Feb 12, 2019
Reviewed
Jun 16, 2020
Last updated
Jan 9, 2023
Haraka version 2.8.8 and earlier comes with a plugin for processing attachments for zip files. Versions 2.8.8 and earlier can be vulnerable to command injection.
References