Description
Haraka version 2.8.8 and earlier comes with a plugin for processing attachments for zip files. Versions 2.8.8 and earlier can be vulnerable to command injection.
Remediation
References
https://github.com/outflanknl/Exploits/blob/master/harakiri-CVE-2016-1000282.py
Related Vulnerabilities
CVE-2020-26289 Vulnerability in maven package org.webjars.npm:date-and-time
CVE-2021-23406 Vulnerability in npm package pac-resolver
CVE-2021-23432 Vulnerability in npm package mootools
CVE-2021-29485 Vulnerability in maven package io.ratpack:ratpack-session
CVE-2020-6428 Vulnerability in maven package org.webjars.npm:electron