Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-28220: Apache James

Apache James prior to release 3.6.3 and 3.7.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. Fix of CVE-2021-38542, which solved similar problem fron Apache James 3.6.1, is subject to a parser differential and do not take into account concurrent requests.

CVE
#apache#sap#ssl

**Apache James Server 3.7.1******August 26, 2022****

The Apache James developers are pleased to announce James server 3.7.1 release.

Early adopters can download it, any issue can be reported on our issue tracker.

The Apache James PMC would like to thanks all contributors who made this release possible!

Announcement

As this is a minor maintenance release.

This release addresses CVE-2022-28220 STARTTLS command injection in Apache JAMES.

It also includes various bugfixes.

Release changelog

The full changes included in this release can be seen in the CHANGELOG.

Related news

GHSA-w45j-f5g5-w94x: Apache James vulnerable to buffering attack

Apache James prior to release 3.6.3 and 3.7.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. Fix of CVE-2021-38542, which solved similar problem fron Apache James 3.6.1, is subject to a parser differential and do not take into account concurrent requests.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907