GHSA-57m2-h3fw-rxhw

Suggest an improvement
Source
https://github.com/advisories/GHSA-57m2-h3fw-rxhw
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/02/GHSA-57m2-h3fw-rxhw/GHSA-57m2-h3fw-rxhw.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-57m2-h3fw-rxhw
Aliases
Published
2025-02-06T12:31:58Z
Modified
2025-02-11T19:25:50.340545Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Apache James vulnerable to denial of service through JMAP HTML to text conversion
Details

Apache James server JMAP HTML to text plain implementation in versions below 3.8.2 and 3.7.6 is subject to unbounded memory consumption that can result in a denial of service.

Users are recommended to upgrade to version 3.7.6 and 3.8.2, which fix this issue.

Database specific
{
    "cwe_ids": [
        "CWE-400"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "nvd_published_at": "2025-02-06T12:15:27Z",
    "github_reviewed_at": "2025-02-06T19:02:30Z"
}
References

Affected packages

Maven / org.apache.james:james-server-jmap-draft

Package

Name
org.apache.james:james-server-jmap-draft
View open source insights on deps.dev
Purl
pkg:maven/org.apache.james/james-server-jmap-draft

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.8.0
Fixed
3.8.2

Affected versions

3.*
3.8.0
3.8.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/02/GHSA-57m2-h3fw-rxhw/GHSA-57m2-h3fw-rxhw.json"

Maven / org.apache.james:james-server-jmap-draft

Package

Name
org.apache.james:james-server-jmap-draft
View open source insights on deps.dev
Purl
pkg:maven/org.apache.james/james-server-jmap-draft

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.7.6

Affected versions

3.*
3.5.0
3.6.0
3.6.2
3.7.0
3.7.1
3.7.2
3.7.3
3.7.4
3.7.5

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/02/GHSA-57m2-h3fw-rxhw/GHSA-57m2-h3fw-rxhw.json"