GHSA-jw7r-rxff-gv24
Dashboard / Vulnerabilities / GHSA-jw7r-rxff-gv24
Summary: Apache James MIME4J improper input validation vulnerability
Details: Improper input validation allows for header injection in MIME4J library when using MIME4J DOM for composing message. This can be exploited by an attacker to add unintended headers to MIME messages.
References: https://nvd.nist.gov/vuln/detail/CVE-2024-21742, https://github.com/apache/james-mime4j/commit/9dec5df2a588fed8027839815daefa79ee66efd1, https://github.com/apache/james-mime4j/commit/d25fb3fd35db42b060789a20634fbe3cb84aba17, https://github.com/apache/james-mime4j, https://lists.apache.org/thread/nrqzg93219wdj056pqfszsd33dc54kfy, http://www.openwall.com/lists/oss-security/2024/02/27/5
Affected packages
Package
Name: org.apache.james:apache-mime4j-core
Purl: pkg:maven/org.apache.james/apache-mime4j-core
Affected ranges
Type: ECOSYSTEM
Events:
