Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r58x-wjg8-63m9

Опубликовано: 08 янв. 2022
Источник: github
Github: Прошло ревью

Описание

Denial of Service in Apache James

In Apache James, using Jazzer fuzzer, we identified that an IMAP user can craft IMAP LIST commands to orchestrate a Denial Of Service using a vulnerable Regular expression. This affected Apache James prior to 3.6.1 We recommend upgrading to Apache James 3.6.1 or higher , which enforce the use of RE2J regular expression engine to execute regex in linear time without back-tracking.

Пакеты

Наименование

org.apache.james:james-server

maven
Затронутые версииВерсия исправления

>= 3.1.0, < 3.6.1

3.6.1

EPSS

Процентиль: 65%
0.00496
Низкий

Связанные уязвимости

CVSS3: 7.5
nvd
около 4 лет назад

In Apache James, using Jazzer fuzzer, we identified that an IMAP user can craft IMAP LIST commands to orchestrate a Denial Of Service using a vulnerable Regular expression. This affected Apache James prior to 3.6.1 We recommend upgrading to Apache James 3.6.1 or higher , which enforce the use of RE2J regular expression engine to execute regex in linear time without back-tracking.

EPSS

Процентиль: 65%
0.00496
Низкий