CVE-2021-40525
Summary
| CVE | CVE-2021-40525 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-01-04 09:15:00 UTC |
| Updated | 2022-03-29 16:34:00 UTC |
| Description | Apache James ManagedSieve implementation alongside with the file storage for sieve scripts is vulnerable to path traversal, allowing reading and writing any file. This vulnerability had been patched in Apache James 3.6.1 and higher. We recommend the upgrade. Distributed and Cassandra based products are also not impacted. |
Risk And Classification
Problem Types: CWE-22
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| oss-security - CVE-2022-22931: Path traversal in Apache James | MLIST | www.openwall.com | |
| oss-security - CVE-2021-40525: Apache James: Sieve file storage vulnerable to path traversal attacks | MISC | www.openwall.com | |
| oss-security - CVE-2021-40525: Apache James: Sieve file storage vulnerable to path traversal attacks | MLIST | www.openwall.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: The Apache James PMC would like to thanks Benoit TELLIER for the report.
There are currently no legacy QID mappings associated with this CVE.