CVE-2024-38462 Information

Description

iRODS before 4.3.2 provides an msiSendMail function with a problematic dependency on the mail binary such as in the mailMS.cppL94-L106 reference.

Reference

https://github.com/irods/irods/issues/7651 https://github.com/irods/irods/issues/7562 https://irods.org/2024/05/irods-4-3-2-is-released/ https://github.com/irods/irods/blob/97eb33f130349db5e01a4b85e89dd1da81460345/server/re/src/mailMS.cpp#L94-L106

Share on: