Security Advisory

CVE-2022-28220

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-09-08 07:40:09
Last updated 2024-08-03 05:48:37
Assigner apache
CVSS score not scored
State PUBLISHED

Description

Apache James prior to release 3.6.3 and 3.7.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. Fix of CVE-2021-38542, which solved similar problem fron Apache James 3.6.1, is subject to a parser differential and do not take into account concurrent requests.