CVE-2024-37358
CVSS 3.1 Score 8.6 of 10 (high)
Details
Published Feb 6, 2025
CWE ID 20
Summary
CVE-2024-37358 is a newly disclosed denial-of-service vulnerability affecting Apache James mail server. This issue, similar to CVE-2024-34055, allows both authenticated and unauthenticated users to misuse IMAP literals, leading to unbounded memory allocation and lengthy computations. The vulnerability can cause service disruption through excessive resource consumption. Versions 3.7.6 and 3.8.2 of Apache James include patches to mitigate this issue by restricting the use of problematic IMAP literals.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- Apache Software Foundation