PT-2022-11250 · Apache · Apache James

Benoit Tellier

·

Published

2022-01-04

·

Updated

2022-03-29

·

CVE-2021-40525

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache James versions prior to 3.6.1
Description The issue concerns a path traversal vulnerability in the Apache James ManagedSieve implementation, which affects the file storage for sieve scripts. This allows for the reading and writing of any file. There is no information provided about the estimated number of potentially affected devices worldwide or details about real-world incidents where this issue was exploited.
Recommendations For versions prior to 3.6.1, upgrade to Apache James 3.6.1 or higher to resolve the issue. As a temporary workaround, consider restricting access to the ManagedSieve implementation and the file storage for sieve scripts to minimize the risk of exploitation.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-40525
GHSA-C38M-7H53-G9V4

Affected Products

Apache James