CVE-2023-51747
Last modified
CVE-2023-51747 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. Apache James prior to versions 3.8.1 and 3.7.5 is vulnerable to SMTP smuggling. A lenient behaviour in line delimiter handling might create a difference of interpretation between the sender and the receiver which can be exploited by an attacker to forge an SMTP envelop, allowing for instance to bypass SPF checks. The patch implies enforcement of CRLF as a line delimiter as part of the DATA transaction. We recommend James users to upgrade to non vulnerable versions.. EPSS estimates a 1.04% chance of exploitation in the next 30 days.
Description
Apache James prior to versions 3.8.1 and 3.7.5 is vulnerable to SMTP smuggling. A lenient behaviour in line delimiter handling might create a difference of interpretation between the sender and the receiver which can be exploited by an attacker to forge an SMTP envelop, allowing for instance to bypass SPF checks. The patch implies enforcement of CRLF as a line delimiter as part of the DATA transaction. We recommend James users to upgrade to non vulnerable versions.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | James | 3.7.5 |
| Apache | James | 3.8.1 |
References
- http://www.openwall.com/lists/oss-security/2024/02/27/4Mailing List, Third Party Advisory
- https://lists.apache.org/thread/rxkwbkh9vgbl9rzx1fkllyk3krhgydkoMailing List, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2024/02/27/4Mailing List, Third Party Advisory
- https://lists.apache.org/thread/rxkwbkh9vgbl9rzx1fkllyk3krhgydkoMailing List, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2023-51747?
How severe is CVE-2023-51747?
How do I fix CVE-2023-51747?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-51741This vulnerability exist in Skyworth Router CM5100, version …7.5
- CVE-2023-51742This vulnerability exist in Skyworth Router CM5100, version …7.5
- CVE-2023-51743This vulnerability exist in Skyworth Router CM5100, version …7.5
- CVE-2023-51744A vulnerability has been identified in JT2Go (All versions <…5.5
- CVE-2023-51745A vulnerability has been identified in JT2Go (All versions <…7.8
- CVE-2023-51746A vulnerability has been identified in JT2Go (All versions <…7.8
- CVE-2023-51748ScaleFusion 10.5.2 does not properly limit users to the Edge…8.8
- CVE-2023-51749ScaleFusion 10.5.2 does not properly limit users to the Edge…8.8
- CVE-2023-5175During process shutdown, it was possible that an `ImageBitma…9.8
- CVE-2023-51750ScaleFusion 10.5.2 does not properly limit users to the Edge…4.6
- CVE-2023-51751ScaleFusion 10.5.2 does not properly limit users to the Edge…6.8
- CVE-2023-51753Rejected reason: This CVE ID has been rejected or withdrawn …
Are you affected by CVE-2023-51747?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
