https://seclists.org/oss-sec/2025/q1/105: CVE-2024-45626: Apache James: denial of service through JMAP HTML to text conversion
Published Feb 5, 2025
·Updated
Affected Software
1 affected component
Apache James>=3.8.0<=3.8.1, <3.7.6
Frequently Asked Questions
1
What is the severity of CVE-2024-45626?
CVE-2024-45626 has a severity rating associated with the potential for denial of service due to unbounded memory consumption.
2
How do I fix CVE-2024-45626?
To fix CVE-2024-45626, upgrade Apache James to version 3.8.2 or later for 3.8.x or to version 3.7.6 for 3.7.x.
3
Which versions of Apache James are affected by CVE-2024-45626?
Apache James server versions 3.8.0 through 3.8.1 and all versions prior to 3.7.6 are affected by CVE-2024-45626.
4
What type of vulnerability is CVE-2024-45626?
CVE-2024-45626 is categorized as a denial of service vulnerability due to excessive memory consumption.
5
What should users of Apache James be aware of regarding CVE-2024-45626?
Users of Apache James should be aware that CVE-2024-45626 can lead to service disruption if unpatched.