VulnerabilityModified
CVE-2024-21742
Improper input validation allows for header injection in MIME4J library when using MIME4J DOM for composing message.
MEDIUM 5.3EPSS 1.09%
Does this matter?
Lower severity and a low EPSS score (1.09%). Track it; it rarely justifies an emergency change on its own.
Description
Improper input validation allows for header injection in MIME4J library when using MIME4J DOM for composing message. This can be exploited by an attacker to add unintended headers to MIME messages.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 1.09% probability · 63th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74
- Affected
- apache/james mime4j
- Source
- security@apache.org
References
- https://lists.apache.org/thread/nrqzg93219wdj056pqfszsd33dc54kfyMailing List, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2024/02/27/5Mailing List
- https://lists.apache.org/thread/nrqzg93219wdj056pqfszsd33dc54kfyMailing List, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.