OESA-2025-2345

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2025-2345
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2025-2345.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2025-2345
Upstream
Published
2025-09-26T13:09:17Z
Modified
2025-09-26T14:16:51.733457Z
Summary
apache-mime4j security update
Details

Java stream based MIME message parser.

Security Fix(es):

A vulnerability was found in Apache James MIME4J up to 0.8.8. It has been rated as problematic.Using CWE to declare the problem leads to CWE-200. The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.Impacted is confidentiality.There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.(CVE-2022-45787)

Database specific
{
    "severity": "Medium"
}
References

Affected packages

openEuler:22.03-LTS-SP4 / apache-mime4j

Package

Name
apache-mime4j
Purl
pkg:rpm/openEuler/apache-mime4j&distro=openEuler-22.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.8.3-3.oe2203sp4

Ecosystem specific

{
    "noarch": [
        "apache-mime4j-0.8.3-3.oe2203sp4.noarch.rpm",
        "apache-mime4j-javadoc-0.8.3-3.oe2203sp4.noarch.rpm"
    ],
    "src": [
        "apache-mime4j-0.8.3-3.oe2203sp4.src.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2025-2345.json"