VDB
CVE-2022-28220
CVE-2022-28220
PUBLISHED
CVSS 7.5 HIGH
Apache James prior to release 3.6.3 and 3.7.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. Fix of CVE-2021-38542, which solved similar problem fron Apache James 3.6.1, is subject to a parser differential and do not take into account concurrent requests.
EPSS 1.82% · 77.2th percentile
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
1.82%
77.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| apache | james | 0, 3.7.0 |
| Maven | org.apache.james:james-server | 3.7.0, 3.7.0, 0 |
| Apache Software Foundation | Apache James | Apache James |
Timeline
- Sep 8, 2022 CVE Published
- Sep 9, 2022 EPSS Score
- Oct 24, 2022 EPSS Score
- Dec 9, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 9, 2023 EPSS Score
- Apr 23, 2023 EPSS Score
- Jun 8, 2023 EPSS Score
- Sep 6, 2023 EPSS Score
- Oct 21, 2023 EPSS Score
- Dec 6, 2023 EPSS Score
- Jan 20, 2024 EPSS Score