PT-2022-11188 · Apache · Apache James
Benoit Tellier
·
Published
2022-01-04
·
Updated
2022-01-12
·
CVE-2021-40111
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Apache James versions prior to 3.6.1
Description
The issue allows for a Denial Of Service attack through crafted APPEND and STATUS IMAP commands, which can trigger infinite loops and result in expensive CPU computations and OutOfMemory exceptions. The IMAP user must be authenticated to exploit this issue.
Recommendations
For versions prior to 3.6.1, upgrade to Apache James 3.6.1 or higher to resolve the issue.
Fix
Infinite Loop
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache James