Description
Fix of CVE-2021-40525 do not prepend delimiters upon valid directory validations. Affected implementations include: - maildir mailbox store - Sieve file repository This enables a user to access other users data stores (limited to user names being prefixed by the value of the username being used).
No analysis available yet.
Remediation
Vendor Workaround
This had been fixed in Apache James 3.6.2.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-1194 | Fix of CVE-2021-40525 do not prepend delimiters upon valid directory validations. Affected implementations include: - maildir mailbox store - Sieve file repository This enables a user to access other users data stores (limited to user names being prefixed by the value of the username being used). |
Github GHSA |
GHSA-v84g-cf5j-xjqx | Path Traversal in Apache James Server |
References
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-03T03:28:42.456Z
Reserved: 2022-01-10T00:00:00.000Z
Link: CVE-2022-22931
No data.
Status : Modified
Published: 2022-02-07T19:15:08.300
Modified: 2024-11-21T06:47:38.117
Link: CVE-2022-22931
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA