imPC@ndo IT

Tracker / CVE-2024-45626

CVE-2024-45626

Medium 6.5

Apache James server JMAP HTML to text plain implementation in versions below 3.8.2 and 3.7.6 is subject to unbounded memory consumption that can result in a denial of service. Users are recommended to upgrade to version 3.7.6 and 3.8.2, which fix this issue.

Affected products and versions

apache james_server · … → 3.7.6
apache james_server · 3.8.0 → 3.8.2

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References