Apache James prior to release 3.6.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. This can result in Man-in -the-middle command injection attacks, leading potentially to leakage of sensible information.
{
"nvd_published_at": "2022-01-04T09:15:00Z",
"severity": "MODERATE",
"cwe_ids": [
"CWE-327",
"CWE-77"
],
"github_reviewed_at": "2022-01-07T18:35:11Z",
"github_reviewed": true
}