CVE-2021-40525
Path traversal in Apache James
9.1
CRITICAL
CVSS 3.1
EPSS 2.8%
Description
Apache James ManagedSieve implementation alongside with the file storage for sieve scripts is vulnerable to path traversal, allowing reading and writing any file. This vulnerability had been patched in Apache James 3.6.1 and higher. We recommend the upgrade. Distributed and Cassandra based products are also not impacted.
How to fix CVE-2021-40525
To remediate CVE-2021-40525, upgrade the affected package to a fixed version below.
- —upgrade to 3.6.1 or later
Is CVE-2021-40525 being exploited?
Low — EPSS is 2.8%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 3.6.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |