Command Execution Vulnerability in Apache SpamAssassin by The Apache Software Foundation
CVE-2020-1930
What is CVE-2020-1930?
A command execution vulnerability has been identified in Apache SpamAssassin versions prior to 3.4.3, allowing an attacker to exploit carefully crafted rule configuration files (.cf). These malicious configurations can trigger system commands to run with the same privileges as the spamd process, posing a significant risk, particularly if the spamd is run with elevated privileges. To mitigate the risk, upgrading to version 3.4.4 is essential. Additionally, users are advised to limit the use of third-party .cf files to trusted sources and to avoid using sa-compile or operating spamd with heightened privileges if an upgrade is not possible.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Apache SpamAssassin prior to 3.4.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved