CVE-2024-45626: Apache James: denial of service through JMAP HTML to text conversion
Published Feb 5, 2025
·Updated
Apache James server JMAP HTML to text plain implementation in versions below 3.8.2 and 3.7.6 is subject to unbounded memory consumption that can result in a denial of service.
Users are recommended to upgrade to version 3.7.6 and 3.8.2, which fix this issue.
Affected Software
5 affected componentsFixes available
maven/org.apache.james:james-server-jmap-draft<3.7.6
3.7.6
maven/org.apache.james:james-server-jmap-draft>=3.8.0<3.8.2
3.8.2
Apache James Server<3.7.6
Apache James Server>=3.8.0<3.8.2
Apache James Server<3.7.6, <3.8.2
Event History
Feb 6, 2025
CVE Published
via MITRE·11:21 AM
Data Sourced
via MITRE·11:21 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·12:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-45626?
CVE-2024-45626 has a high severity rating due to its potential for causing unbounded memory consumption leading to denial of service.
2
How do I fix CVE-2024-45626?
To fix CVE-2024-45626, upgrade Apache James Server to version 3.7.6 or 3.8.2 or later.
3
What are the affected versions for CVE-2024-45626?
CVE-2024-45626 affects Apache James Server versions below 3.8.2 and 3.7.6.
4
What impact does CVE-2024-45626 have on systems?
CVE-2024-45626 can lead to denial of service due to unbounded memory consumption.
5
Who is impacted by CVE-2024-45626?
Users of Apache James Server versions below 3.8.2 and 3.7.6 are impacted by CVE-2024-45626.