HIGH7.5
GHSA-w45j-f5g5-w94x
Apache James vulnerable to buffering attack
Quick fix
GHSA-w45j-f5g5-w94x — org.apache.james:james-server: upgrade to the fixed version with the command below.
# pom.xml: bump <version>3.6.3</version> for org.apache.james:james-serverDetails
Apache James prior to release 3.6.3 and 3.7.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. Fix of CVE-2021-38542, which solved similar problem fron Apache James 3.6.1, is subject to a parser differential and do not take into account concurrent requests.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.apache.james:james-server
Introduced in:
0Fixed in: 3.6.3Fix
# pom.xml: bump <version>3.6.3</version> for org.apache.james:james-serverMaven/org.apache.james:james-server
Introduced in:
3.7.0Fixed in: 3.7.1Fix
# pom.xml: bump <version>3.7.1</version> for org.apache.james:james-server