https://seclists.org/oss-sec/2025/q1/104: CVE-2024-37358: Apache James: denial of service through the use of IMAP literals
Published Feb 5, 2025
·Updated
Affected Software
1 affected component
Apache James Server<=3.7.5, >=3.8.0<=3.8.1
Frequently Asked Questions
1
What is the severity of CVE-2024-37358?
CVE-2024-37358 has been rated as a denial of service vulnerability, allowing attackers to disrupt service.
2
How do I fix CVE-2024-37358?
To fix CVE-2024-37358, upgrade to Apache James server version 3.8.2 or later.
3
Which versions of Apache James are affected by CVE-2024-37358?
CVE-2024-37358 affects Apache James server versions up to 3.7.5 and from 3.8.0 to 3.8.1.
4
Can both authenticated and unauthenticated users exploit CVE-2024-37358?
Yes, CVE-2024-37358 can be exploited by both authenticated and unauthenticated users.
5
What type of attack does CVE-2024-37358 enable?
CVE-2024-37358 enables denial of service attacks through the use of IMAP literals.