CVE-2024-37358: Apache James: denial of service through the use of IMAP literals
Similarly to CVE-2024-34055, Apache James is vulnerable to denial of service through the abuse of IMAP literals from both authenticated and unauthenticated users, which could be used to cause unbounded memory allocation and very long computations
Version 3.7.6 and 3.8.2 restrict such illegitimate use of IMAP literals.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37358?
CVE-2024-37358 has been classified as a denial of service vulnerability that poses a high risk due to potential unbounded memory allocation.
How do I fix CVE-2024-37358?
To mitigate CVE-2024-37358, upgrade Apache James to version 3.8.2 or later, which includes restrictions to prevent the abuse of IMAP literals.
Which versions of Apache James are affected by CVE-2024-37358?
CVE-2024-37358 affects Apache James versions between 3.7.6 and 3.8.2.
What attack methods are associated with CVE-2024-37358?
CVE-2024-37358 can be exploited by both authenticated and unauthenticated users abusing IMAP literals to cause denial of service.
What are the potential consequences of exploiting CVE-2024-37358?
Exploiting CVE-2024-37358 can lead to service outages due to excessive memory usage and prolonged computations.