PT-2022-11188 · Apache · Apache James

Benoit Tellier

·

Published

2022-01-04

·

Updated

2022-01-12

·

CVE-2021-40111

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apache James versions prior to 3.6.1
Description The issue allows for a Denial Of Service attack through crafted APPEND and STATUS IMAP commands, which can trigger infinite loops and result in expensive CPU computations and OutOfMemory exceptions. The IMAP user must be authenticated to exploit this issue.
Recommendations For versions prior to 3.6.1, upgrade to Apache James 3.6.1 or higher to resolve the issue.

Fix

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-40111
GHSA-FQGW-6QJ5-8HMP

Affected Products

Apache James