{"id":"GHSA-w5m8-5v9m-xhx5","summary":"Critical severity vulnerability that affects Haraka","details":"Haraka version 2.8.8 and earlier comes with a plugin for processing attachments for zip files. Versions 2.8.8 and earlier can be vulnerable to command injection.","aliases":["CVE-2016-1000282"],"modified":"2023-11-08T03:58:08.641572Z","published":"2019-02-12T17:26:10Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-77"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2020-06-16T21:59:42Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-1000282"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-w5m8-5v9m-xhx5"},{"type":"WEB","url":"https://github.com/outflanknl/Exploits/blob/master/harakiri-CVE-2016-1000282.py"}],"affected":[{"package":{"name":"Haraka","ecosystem":"npm","purl":"pkg:npm/Haraka"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.8.9"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/02/GHSA-w5m8-5v9m-xhx5/GHSA-w5m8-5v9m-xhx5.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}