← back
CVE-2022-22931

Path traversal in Apache James 3.6.1

EPSS 1.7%CWE-22
Fix of CVE-2021-40525 do not prepend delimiters upon valid directory validations. Affected implementations include: - maildir mailbox store - Sieve file repository This enables a user to access other users data stores (limited to user names being prefixed by the value of the username being used).

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →