CVE-2021-40110
Denial of Service in Apache James
EPSS 2.9%
描述
In Apache James, using Jazzer fuzzer, we identified that an IMAP user can craft IMAP LIST commands to orchestrate a Denial Of Service using a vulnerable Regular expression. This affected Apache James prior to 3.6.1 We recommend upgrading to Apache James 3.6.1 or higher , which enforce the use of RE2J regular expression engine to execute regex in linear time without back-tracking.
如何修補 CVE-2021-40110
要修補 CVE-2021-40110,請將受影響套件升級到下列已修補版本。
- Maven/org.apache.james:james-server—升級至 3.6.1 或更新版本
CVE-2021-40110 正在被利用嗎?
低 — EPSS 為 2.9%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- >= 3.1.0, < 3.6.1