← back
CVE-2024-21742

Apache James Mime4J: Mime4J DOM header injection

CVSS 5.3 MEDIUMEPSS 1.1%CWE-74
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.3EPSS 1.1%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
27 Feb 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Improper input validation allows for header injection in MIME4J library when using MIME4J DOM for composing message. This can be exploited by an attacker to add unintended headers to MIME messages.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →