CVE-2024-37358

CVSS 3.1 Score 8.6 of 10 (high)

Details

Published Feb 6, 2025
CWE ID 20

Summary

CVE-2024-37358 is a newly disclosed denial-of-service vulnerability affecting Apache James mail server. This issue, similar to CVE-2024-34055, allows both authenticated and unauthenticated users to misuse IMAP literals, leading to unbounded memory allocation and lengthy computations. The vulnerability can cause service disruption through excessive resource consumption. Versions 3.7.6 and 3.8.2 of Apache James include patches to mitigate this issue by restricting the use of problematic IMAP literals.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share