CVE-2021-40525

Description

Apache James ManagedSieve implementation alongside with the file storage for sieve scripts is vulnerable to path traversal, allowing reading and writing any file. This vulnerability had been patched in Apache James 3.6.1 and higher. We recommend the upgrade. Distributed and Cassandra based products are also not impacted.

Risk Information

Base Score
9.1
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Score
Exploitation Probability
2.773

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2021-40525,CVE-2021-40111,CVE-2021-38542,CVE-2021-40110 are fixed in Apache-james-server 3.6.1Windows
Vulnerabilities CVE-2021-40525,CVE-2021-40111,CVE-2021-38542,CVE-2021-40110 are fixed in Apache-james-server for Linux 3.6.1Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234