VDB
Sign up
HIGH7.5

GHSA-w45j-f5g5-w94x

Apache James vulnerable to buffering attack

Quick fix

GHSA-w45j-f5g5-w94x — org.apache.james:james-server: upgrade to the fixed version with the command below.

# pom.xml: bump <version>3.6.3</version> for org.apache.james:james-server

Details

Apache James prior to release 3.6.3 and 3.7.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. Fix of CVE-2021-38542, which solved similar problem fron Apache James 3.6.1, is subject to a parser differential and do not take into account concurrent requests.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.apache.james:james-server
Introduced in: 0Fixed in: 3.6.3
Fix# pom.xml: bump <version>3.6.3</version> for org.apache.james:james-server
Maven/org.apache.james:james-server
Introduced in: 3.7.0Fixed in: 3.7.1
Fix# pom.xml: bump <version>3.7.1</version> for org.apache.james:james-server

References