PT-2021-24133 · Apache+1 · Apache Sling Commons Messaging Mail+1

Michael Lescisin

·

Published

2021-12-14

·

Updated

2025-11-01

·

CVE-2021-44549

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Apache Sling Commons Messaging Mail version 1.0
Description: The issue concerns the lack of an option to enable server identity checks for the shared mail session in Apache Sling Commons Messaging Mail. This increases the risk of "man in the middle" attacks when accessing mail servers via SMTPS. For compatibility reasons, these checks are disabled by default in JavaMail/Jakarta Mail. However, a user can enable these checks by accessing the session via the message created by SimpleMessageBuilder and setting the property mail.smtps.ssl.checkserveridentity to true.
Recommendations: For Apache Sling Commons Messaging Mail version 1.0, consider upgrading to version 2.0, which adds support for enabling server identity checks by default. As a temporary workaround for version 1.0, users can enable server identity checks by accessing the session via the message created by SimpleMessageBuilder and setting the property mail.smtps.ssl.checkserveridentity to true.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-13422
ALT-PU-2025-2871
CVE-2021-44549
GHSA-C69W-JJ56-834W
RHSA-2024:8884
RHSA-2024:8885
RHSA-2024:8886
RHSA-2024:8887

Affected Products

Alt Linux
Apache Sling Commons Messaging Mail