VDB
Sign up
HIGH

GHSA-r58x-wjg8-63m9

Denial of Service in Apache James

Quick fix

GHSA-r58x-wjg8-63m9 — org.apache.james:james-server: upgrade to the fixed version with the command below.

# pom.xml: bump <version>3.6.1</version> for org.apache.james:james-server

Details

In Apache James, using Jazzer fuzzer, we identified that an IMAP user can craft IMAP LIST commands to orchestrate a Denial Of Service using a vulnerable Regular expression. This affected Apache James prior to 3.6.1 We recommend upgrading to Apache James 3.6.1 or higher , which enforce the use of RE2J regular expression engine to execute regex in linear time without back-tracking.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.apache.james:james-server
Introduced in: 3.1.0Fixed in: 3.6.1
Fix# pom.xml: bump <version>3.6.1</version> for org.apache.james:james-server

References