CVE-2024-37358
published 2025-02-06CVE-2024-37358: Similarly to CVE-2024-34055, Apache James is vulnerable to denial of service through the abuse of IMAP literals from both authenticated and unauthenticated…
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.86%
54.3th percentile
Similarly to CVE-2024-34055, Apache James is vulnerable to denial of service through the abuse of IMAP literals from both authenticated and unauthenticated users, which could be used to cause unbounded memory allocation and very long computations
Version 3.7.6 and 3.8.2 restrict such illegitimate use of IMAP literals.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | james_server | < 3.7.6 | 3.7.6 |
| apache | james_server | >= 3.8.0 < 3.8.2 | 3.8.2 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
ghsa6.5MEDIUM
osv6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache James vulnerable to denial of service through the use of IMAP literals
ghsa·2025-02-06·CVSS 6.5
CVE-2024-37358 [MEDIUM] CWE-20 Apache James vulnerable to denial of service through the use of IMAP literals
Apache James vulnerable to denial of service through the use of IMAP literals
Similarly to CVE-2024-34055, Apache James is vulnerable to denial of service through the abuse of IMAP literals from both authenticated and unauthenticated users, which could be used to cause unbounded memory allocation and very long computations
Version 3.7.6 and 3.8.2 restrict such illegitimate use of IMAP literals.
OSV
Apache James vulnerable to denial of service through the use of IMAP literals
osv·2025-02-06·CVSS 6.5
CVE-2024-37358 [MEDIUM] Apache James vulnerable to denial of service through the use of IMAP literals
Apache James vulnerable to denial of service through the use of IMAP literals
Similarly to CVE-2024-34055, Apache James is vulnerable to denial of service through the abuse of IMAP literals from both authenticated and unauthenticated users, which could be used to cause unbounded memory allocation and very long computations
Version 3.7.6 and 3.8.2 restrict such illegitimate use of IMAP literals.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-02-06
Published