NA

CVE-2024-21742

Published: 27/02/2024 Updated: 29/02/2024

Vulnerability Summary

Improper input validation allows for header injection in MIME4J library when using MIME4J DOM for composing message. This can be exploited by an malicious user to add unintended headers to MIME messages.

Vendor Advisories

Debian Bug report logs - #1064966 apache-mime4j: CVE-2024-21742 Package: src:apache-mime4j; Maintainer for src:apache-mime4j is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Wed, 28 Feb 2024 14:45:01 UTC Severity: important Tags: securit ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> CVE-2024-21742: Apache James Mime4J: Mime4J DOM header injection <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: ...