Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w45j-f5g5-w94x

Опубликовано: 09 сент. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Apache James vulnerable to buffering attack

Apache James prior to release 3.6.3 and 3.7.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. Fix of CVE-2021-38542, which solved similar problem fron Apache James 3.6.1, is subject to a parser differential and do not take into account concurrent requests.

Пакеты

Наименование

org.apache.james:james-server

maven
Затронутые версииВерсия исправления

< 3.6.3

3.6.3

Наименование

org.apache.james:james-server

maven
Затронутые версииВерсия исправления

= 3.7.0

3.7.1

EPSS

Процентиль: 83%
0.01851
Низкий

7.5 High

CVSS3

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 7.5
nvd
больше 3 лет назад

Apache James prior to release 3.6.3 and 3.7.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. Fix of CVE-2021-38542, which solved similar problem fron Apache James 3.6.1, is subject to a parser differential and do not take into account concurrent requests.

EPSS

Процентиль: 83%
0.01851
Низкий

7.5 High

CVSS3

Дефекты

CWE-77