Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v84g-cf5j-xjqx

Опубликовано: 08 фев. 2022
Источник: github
Github: Прошло ревью

Описание

Path Traversal in Apache James Server

Apache James Server prior to version 3.6.2 contains a path traversal vulnerability. The fix for CVE-2021-40525 does not prepend delimiters upon valid directory validations. Affected implementations include: - maildir mailbox store - Sieve file repository This enables a user to access other users data stores (limited to user names being prefixed by the value of the username being used).

Пакеты

Наименование

org.apache.james:james-server

maven
Затронутые версииВерсия исправления

< 3.6.2

3.6.2

EPSS

Процентиль: 86%
0.02834
Низкий

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 4.3
nvd
почти 4 года назад

Fix of CVE-2021-40525 do not prepend delimiters upon valid directory validations. Affected implementations include: - maildir mailbox store - Sieve file repository This enables a user to access other users data stores (limited to user names being prefixed by the value of the username being used).

EPSS

Процентиль: 86%
0.02834
Низкий

Дефекты

CWE-22