CVE-2022-22931

CVE-2022-22931: Path traversal in Apache James 3.6.1

Vendor Apache Software Foundation
Product Apache James
Weakness CWE-22 · Path traversal
Published February 7, 2022
Last update August 3, 2024

CVSS base score

What the vulnerability does

Description

Fix of CVE-2021-40525 do not prepend delimiters upon valid directory validations. Affected implementations include: - maildir mailbox store - Sieve file repository This enables a user to access other users data stores (limited to user names being prefixed by the value of the username being used).

Key dates

Disclosure timeline

February 7, 2022 CVE published
August 3, 2024 Record updated