CVE-2021-38542: Apache James vulnerable to STARTTLS command injection (IMAP and POP3)
Published Jan 4, 2022
·Updated
Apache James prior to release 3.6.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. This can result in Man-in -the-middle command injection attacks, leading potentially to leakage of sensible information.
Affected Software
1 affected component
Apache James<3.6.1
Event History
Jan 4, 2022
CVE Published
via MITRE·08:55 AM
Data Sourced
via MITRE·08:55 AM
DescriptionWeakness
Frequently Asked Questions
1
What is Apache James?
Apache James is an open-source email server and email client framework written in Java.
2
What is the vulnerability with ID CVE-2021-38542?
The vulnerability with ID CVE-2021-38542 is a buffering attack vulnerability in Apache James prior to version 3.6.1.
3
What is the impact of CVE-2021-38542?
The impact of CVE-2021-38542 is that it can result in man-in-the-middle command injection attacks and potential leakage of sensitive information.
4
What is the severity of CVE-2021-38542?
The severity of CVE-2021-38542 is medium with a CVSS score of 5.9.
5
How can I fix CVE-2021-38542?
To fix CVE-2021-38542, you should upgrade Apache James to version 3.6.1 or later.