Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-37358


Similarly to CVE-2024-34055, Apache James is vulnerable to denial of service through the abuse of IMAP literals from both authenticated and unauthenticated users, which could be used to cause unbounded memory allocation and very long computations Version 3.7.6 and 3.8.2 restrict such illegitimate use of IMAP literals.


Published

2025-02-06T12:15:26.343

Last Modified

2025-07-16T13:58:52.197

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 8.6 (HIGH)

Weaknesses
  • Type: Primary
    CWE-20
  • Type: Primary
    CWE-770

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache james_server < 3.7.6 Yes
Application apache james_server < 3.8.2 Yes

References