CVE-2021-40110 Information

Description

In Apache James using Jazzer fuzzer we identified that an IMAP user can craft IMAP LIST commands to orchestrate a Denial Of Service using a vulnerable Regular expression. This affected Apache James prior to 3.6.1 We recommend upgrading to Apache James 3.6.1 or higher which enforce the use of RE2J regular expression engine to execute regex in linear time without back-tracking.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Reference

https://www.openwall.com/lists/oss-security/2022/01/04/2 http://www.openwall.com/lists/oss-security/2022/01/04/2

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

NONE

Base Score

HIGH

Base Severity

7.5

Share on: