Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p5q9-86w4-2xr5

Опубликовано: 27 фев. 2024
Источник: github
Github: Прошло ревью
CVSS3: 7.1

Описание

SMTP smuggling in Apache James

Apache James prior to versions 3.8.1 and 3.7.5 is vulnerable to SMTP smuggling.

A lenient behaviour in line delimiter handling might create a difference of interpretation between the sender and the receiver which can be exploited by an attacker to forge an SMTP envelop, allowing for instance to bypass SPF checks.

The patch implies enforcement of CRLF as a line delimiter as part of the DATA transaction.

We recommend James users to upgrade to non vulnerable versions.

Пакеты

Наименование

org.apache.james:james-server

maven
Затронутые версииВерсия исправления

< 3.7.5

3.7.5

Наименование

org.apache.james:james-server

maven
Затронутые версииВерсия исправления

= 3.8.0

3.8.1

EPSS

Процентиль: 47%
0.00243
Низкий

7.1 High

CVSS3

Дефекты

CWE-20
CWE-290

Связанные уязвимости

CVSS3: 7.4
redhat
почти 2 года назад

Apache James prior to versions 3.8.1 and 3.7.5 is vulnerable to SMTP smuggling. A lenient behaviour in line delimiter handling might create a difference of interpretation between the sender and the receiver which can be exploited by an attacker to forge an SMTP envelop, allowing for instance to bypass SPF checks. The patch implies enforcement of CRLF as a line delimiter as part of the DATA transaction. We recommend James users to upgrade to non vulnerable versions.

CVSS3: 7.1
nvd
почти 2 года назад

Apache James prior to versions 3.8.1 and 3.7.5 is vulnerable to SMTP smuggling. A lenient behaviour in line delimiter handling might create a difference of interpretation between the sender and the receiver which can be exploited by an attacker to forge an SMTP envelop, allowing for instance to bypass SPF checks. The patch implies enforcement of CRLF as a line delimiter as part of the DATA transaction. We recommend James users to upgrade to non vulnerable versions.

EPSS

Процентиль: 47%
0.00243
Низкий

7.1 High

CVSS3

Дефекты

CWE-20
CWE-290