Apache James: denial of service through JMAP HTML to text conversion
Vulnerability Description
Apache James server JMAP HTML to text plain implementation in versions below 3.8.2 and 3.7.6 is subject to unbounded memory consumption that can result in a denial of service. Users are recommended to upgrade to version 3.7.6 and 3.8.2, which fix this issue.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-45626
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Benoit TELLIER
- Wojciech Kapcia
More from Apache Software Foundation
View All →Affected Vendor
Apache Software Foundation
View all reports →