CVE-2024-21742

Improper input validation allows for header injection in MIME4J library when using MIME4J DOM for composing message. This can be exploited by an attacker to add unintended headers to MIME messages.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:james_mime4j:*:*:*:*:*:*:*:*

History

14 Feb 2025, 15:27

Type Values Removed Values Added
References () http://www.openwall.com/lists/oss-security/2024/02/27/5 - () http://www.openwall.com/lists/oss-security/2024/02/27/5 - Mailing List
References () https://lists.apache.org/thread/nrqzg93219wdj056pqfszsd33dc54kfy - () https://lists.apache.org/thread/nrqzg93219wdj056pqfszsd33dc54kfy - Mailing List, Vendor Advisory
CWE CWE-74
CPE cpe:2.3:a:apache:james_mime4j:*:*:*:*:*:*:*:*
First Time Apache james Mime4j
Apache
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3

13 Feb 2025, 18:16

Type Values Removed Values Added
Summary (en) Improper input validation allows for header injection in MIME4J library when using MIME4J DOM for composing message. This can be exploited by an attacker to add unintended headers to MIME messages. (en) Improper input validation allows for header injection in MIME4J library when using MIME4J DOM for composing message. This can be exploited by an attacker to add unintended headers to MIME messages.

21 Nov 2024, 08:54

Type Values Removed Values Added
References () http://www.openwall.com/lists/oss-security/2024/02/27/5 - () http://www.openwall.com/lists/oss-security/2024/02/27/5 -
References () https://lists.apache.org/thread/nrqzg93219wdj056pqfszsd33dc54kfy - () https://lists.apache.org/thread/nrqzg93219wdj056pqfszsd33dc54kfy -

29 Feb 2024, 01:44

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2024/02/27/5 -

28 Feb 2024, 14:06

Type Values Removed Values Added
Summary
  • (es) La validación de entrada incorrecta permite la inyección de encabezado en la librería MIME4J cuando se usa MIME4J DOM para redactar mensajes. Un atacante puede aprovechar esto para agregar encabezados no deseados a los mensajes MIME.

27 Feb 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-27 17:15

Updated : 2025-03-25 16:15


NVD link : CVE-2024-21742

Mitre link : CVE-2024-21742

CVE.ORG link : CVE-2024-21742


JSON object : View

Products Affected

apache

  • james_mime4j
CWE
CWE-20

Improper Input Validation

CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')