CVE-2021-38542
Summary
| CVE | CVE-2021-38542 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-01-04 09:15:00 UTC |
| Updated | 2022-10-27 11:39:00 UTC |
| Description | Apache James prior to release 3.6.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. This can result in Man-in -the-middle command injection attacks, leading potentially to leakage of sensible information. |
Risk And Classification
Problem Types: CWE-327
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| oss-security - CVE-2021-38542: Apache James vulnerable to STARTTLS command injection (IMAP and POP3) | MLIST | www.openwall.com | |
| oss-security - CVE-2022-28220: STARTTLS command injection in Apache JAMES | MLIST | www.openwall.com | |
| oss-security - CVE-2021-38542: Apache James vulnerable to STARTTLS command injection (IMAP and POP3) | MISC | www.openwall.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: We thanks Benoit Tellier, Raphael Ouazana for reporting this vulnerability as well as Damian Poddebniak, Fabian Ising, Hanno Böck, and Sebastian Schinzel Münster University of Applied Science for their research and tools regarding STARTTLS security.
There are currently no legacy QID mappings associated with this CVE.