Vulnerabilities > CVE-2024-38462 - Unspecified vulnerability in Irods 4.1.10/4.2.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
iRODS before 4.3.2 provides an msiSendMail function with a problematic dependency on the mail binary, such as in the mailMS.cpp#L94-L106 reference.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 |
References
- https://github.com/irods/irods/blob/97eb33f130349db5e01a4b85e89dd1da81460345/server/re/src/mailMS.cpp#L94-L106
- https://github.com/irods/irods/issues/7562
- https://github.com/irods/irods/issues/7651
- https://irods.org/2024/05/irods-4-3-2-is-released/
- https://github.com/irods/irods/blob/97eb33f130349db5e01a4b85e89dd1da81460345/server/re/src/mailMS.cpp#L94-L106
- https://irods.org/2024/05/irods-4-3-2-is-released/
- https://github.com/irods/irods/issues/7651
- https://github.com/irods/irods/issues/7562