Path Traversal in Apache James Server
Moderate severity
GitHub Reviewed
Published
Feb 8, 2022
to the GitHub Advisory Database
•
Updated Feb 3, 2023
Description
Published by the National Vulnerability Database
Feb 7, 2022
Published to the GitHub Advisory Database
Feb 8, 2022
Reviewed
Feb 8, 2022
Last updated
Feb 3, 2023
Apache James Server prior to version 3.6.2 contains a path traversal vulnerability. The fix for CVE-2021-40525 does not prepend delimiters upon valid directory validations. Affected implementations include: - maildir mailbox store - Sieve file repository This enables a user to access other users data stores (limited to user names being prefixed by the value of the username being used).
References