Описание
Path Traversal in Apache James Server
Apache James Server prior to version 3.6.2 contains a path traversal vulnerability. The fix for CVE-2021-40525 does not prepend delimiters upon valid directory validations. Affected implementations include: - maildir mailbox store - Sieve file repository This enables a user to access other users data stores (limited to user names being prefixed by the value of the username being used).
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2022-22931
- https://github.com/apache/james-project/pull/877
- https://github.com/apache/james-project/pull/877/commits/b1e891a9e5eeadfa1d779ae50f21c73efe4d2fc7
- https://lists.apache.org/thread/bp8yql4wws56jlh0vxoowj7foothsmpr
- https://www.openwall.com/lists/oss-security/2022/02/07/1
Пакеты
org.apache.james:james-server
< 3.6.2
3.6.2
Связанные уязвимости
Fix of CVE-2021-40525 do not prepend delimiters upon valid directory validations. Affected implementations include: - maildir mailbox store - Sieve file repository This enables a user to access other users data stores (limited to user names being prefixed by the value of the username being used).