Apache Software Foundation Apache James Server vulnerabilities

7 known vulnerabilities affecting apache_software_foundation/apache_james_server.

Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH3MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2024-45626HIGHCVSS 7.5≥ 3.8.0, ≤ 3.8.1≤ 3.7.52025-02-06
CVE-2024-45626 [MEDIUM] CWE-400 CVE-2024-45626: Apache James server JMAP HTML to text plain implementation in versions below 3.8.2 and 3.7.6 is subj Apache James server JMAP HTML to text plain implementation in versions below 3.8.2 and 3.7.6 is subject to unbounded memory consumption that can result in a denial of service. Users are recommended to upgrade to version 3.7.6 and 3.8.2, which fix this issue.
cvelistv5nvd
CVE-2024-37358MEDIUMCVSS 6.5≤ 3.7.5≥ 3.8.0, ≤ 3.8.12025-02-06
CVE-2024-37358 [MEDIUM] CWE-770 Apache James: denial of service through the use of IMAP literals Apache James: denial of service through the use of IMAP literals Similarly to CVE-2024-34055, Apache James is vulnerable to denial of service through the abuse of IMAP literals from both authenticated and unauthenticated users, which could be used to cause unbounded memory allocation and very long computations Version 3.7.6 and 3.8.2 restrict such illegitimate use of IMAP literals.
cvelistv5
CVE-2024-34055MEDIUMCVSS 6.5≤ 3.7.5≥ 3.8.0, ≤ 3.8.12024-06-05
CVE-2024-34055 [MEDIUM] CWE-770 CVE-2024-34055: Cyrus IMAP before 3.8.3 and 3.10.x before 3.10.0-rc1 allows authenticated attackers to cause unbound Cyrus IMAP before 3.8.3 and 3.10.x before 3.10.0-rc1 allows authenticated attackers to cause unbounded memory allocation by sending many LITERALs in a single command.
nvd
CVE-2023-51518CRITICALCVSS 9.8≤ 3.7.4≥ 3.8, ≤ 3.8.02024-02-27
CVE-2023-51518 [CRITICAL] CWE-502 CVE-2023-51518: Apache James prior to version 3.7.5 and 3.8.0 exposes a JMX endpoint on localhost subject to pre-aut Apache James prior to version 3.7.5 and 3.8.0 exposes a JMX endpoint on localhost subject to pre-authentication deserialisation of untrusted data. Given a deserialisation gadjet, this could be leveraged as part of an exploit chain that could result in privilege escalation. Note that by default JMX endpoint is only bound locally. We recommend user
cvelistv5nvd
CVE-2023-51747HIGHCVSS 7.1≤ 3.7.4≥ 3.8, ≤ 3.8.02024-02-27
CVE-2023-51747 [HIGH] CWE-20 CVE-2023-51747: Apache James prior to versions 3.8.1 and 3.7.5 is vulnerable to SMTP smuggling. A lenient behaviour Apache James prior to versions 3.8.1 and 3.7.5 is vulnerable to SMTP smuggling. A lenient behaviour in line delimiter handling might create a difference of interpretation between the sender and the receiver which can be exploited by an attacker to forge an SMTP envelop, allowing for instance to bypass SPF checks. The patch implies enforcement of CRLF
cvelistv5nvd
CVE-2023-26269HIGHCVSS 7.8≤ 3.7.32023-04-03
CVE-2023-26269 [HIGH] CWE-862 Apache James server: Privilege escalation through unauthenticated JMX Apache James server: Privilege escalation through unauthenticated JMX Apache James server version 3.7.3 and earlier provides a JMX management service without authentication by default. This allows privilege escalation by a malicious local user. Administrators are advised to disable JMX, or set up a JMX password. Note that version 3.7.4 onward will set up a JMX password automatically for Guice u
cvelistv5
CVE-2022-45935MEDIUMCVSS 5.5≤ 3.7.22023-01-06
CVE-2022-45935 [MEDIUM] CWE-668 CVE-2022-45935: Usage of temporary files with insecure permissions by the Apache James server allows an attacker wit Usage of temporary files with insecure permissions by the Apache James server allows an attacker with local access to access private user data in transit. Vulnerable components includes the SMTP stack and IMAP APPEND command. This issue affects Apache James server version 3.7.2 and prior versions.
cvelistv5nvd
Apache Software Foundation Apache James Server vulnerabilities | cvebase