CVE-2021-40110: Apache James IMAP vulnerable to a ReDoS
In Apache James, using Jazzer fuzzer, we identified that an IMAP user can craft IMAP LIST commands to orchestrate a Denial Of Service using a vulnerable Regular expression. This affected Apache James prior to 3.6.1 We recommend upgrading to Apache James 3.6.1 or higher , which enforce the use of RE2J regular expression engine to execute regex in linear time without back-tracking.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-40110?
CVE-2021-40110 is a vulnerability in Apache James, where an IMAP user can craft IMAP LIST commands to orchestrate a Denial of Service attack using a vulnerable regular expression.
What is the severity of CVE-2021-40110?
The severity of CVE-2021-40110 is high, with a severity score of 7.5.
What software is affected by CVE-2021-40110?
Apache James versions prior to 3.6.1 are affected by CVE-2021-40110.
How can I fix CVE-2021-40110?
To fix CVE-2021-40110, upgrade to Apache James 3.6.1 or higher, which enforces the use of RE2.
Where can I find more information about CVE-2021-40110?
You can find more information about CVE-2021-40110 in the references: [link1](http://www.openwall.com/lists/oss-security/2022/01/04/2) and [link2](https://www.openwall.com/lists/oss-security/2022/01/04/2).