PT-2022-10736 · Apache · Apache James
Benoit Tellier
+1
·
Published
2022-01-04
·
Updated
2022-10-27
·
CVE-2021-38542
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache James versions prior to 3.6.1
Description
The issue allows for a buffering attack using the STARTTLS command, potentially leading to Man-in-the-middle command injection attacks. This could result in the leakage of sensitive information.
Recommendations
For versions prior to 3.6.1, update to release 3.6.1 or later to resolve the issue.
Fix
Use of a Broken Cryptographic Algorithm
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache James