CVE-2023-51747
Last modified
CVE-2023-51747 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. Apache James prior to versions 3.8.1 and 3.7.5 is vulnerable to SMTP smuggling. A lenient behaviour in line delimiter handling might create a difference of interpretation between the sender and the receiver which can be exploited by an attacker to forge an SMTP envelop, allowing for instance to bypass SPF checks. The patch implies enforcement of CRLF as a line delimiter as part of the DATA transaction. We recommend James users to upgrade to non vulnerable versions.. EPSS estimates a 1.04% chance of exploitation in the next 30 days.
Description
Apache James prior to versions 3.8.1 and 3.7.5 is vulnerable to SMTP smuggling. A lenient behaviour in line delimiter handling might create a difference of interpretation between the sender and the receiver which can be exploited by an attacker to forge an SMTP envelop, allowing for instance to bypass SPF checks. The patch implies enforcement of CRLF as a line delimiter as part of the DATA transaction. We recommend James users to upgrade to non vulnerable versions.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | James | 3.7.5 |
| Apache | James | 3.8.1 |
References
- http://www.openwall.com/lists/oss-security/2024/02/27/4Mailing List, Third Party Advisory
- https://lists.apache.org/thread/rxkwbkh9vgbl9rzx1fkllyk3krhgydkoMailing List, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2024/02/27/4Mailing List, Third Party Advisory
- https://lists.apache.org/thread/rxkwbkh9vgbl9rzx1fkllyk3krhgydkoMailing List, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2023-51747?
How severe is CVE-2023-51747?
How do I fix CVE-2023-51747?
Are you affected by CVE-2023-51747?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
