CVE-2024-38462: Irods

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

iRODS before 4.3.2 provides an msiSendMail function with a problematic dependency on the mail binary, such as in the mailMS.cpp#L94-L106 reference.

Affected products

  • Irods Irods: before 4.3.2 (fixed in 4.3.2)

Published 2024-06-16. Last modified 2026-06-17.