CVE-2024-21742

CVE-2024-21742: Apache James Mime4J: Mime4J DOM header injection

Vendor Apache Software Foundation
Product Apache James Mime4J
Weakness CWE-74
Published February 27, 2024
Last update May 6, 2025

CVSS base score

What the vulnerability does

Description

Improper input validation allows for header injection in MIME4J library when using MIME4J DOM for composing message. This can be exploited by an attacker to add unintended headers to MIME messages.

Key dates

Disclosure timeline

February 27, 2024 CVE published
May 6, 2025 Record updated