{"id":"GHSA-v84g-cf5j-xjqx","summary":"Path Traversal in Apache James Server","details":"Apache James Server prior to version 3.6.2 contains a path traversal vulnerability. The fix for CVE-2021-40525 does not prepend delimiters upon valid directory validations. Affected implementations include: - maildir mailbox store - Sieve file repository This enables a user to access other users data stores (limited to user names being prefixed by the value of the username being used).","aliases":["CVE-2022-22931"],"modified":"2024-12-05T05:43:34.872584Z","published":"2022-02-08T00:00:34Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2022-02-08T20:38:52Z","nvd_published_at":"2022-02-07T19:15:00Z","cwe_ids":["CWE-22"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-22931"},{"type":"WEB","url":"https://github.com/apache/james-project/pull/877"},{"type":"WEB","url":"https://github.com/apache/james-project/pull/877/commits/b1e891a9e5eeadfa1d779ae50f21c73efe4d2fc7"},{"type":"PACKAGE","url":"https://github.com/apache/james-project"},{"type":"WEB","url":"https://lists.apache.org/thread/bp8yql4wws56jlh0vxoowj7foothsmpr"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2022/02/07/1"}],"affected":[{"package":{"name":"org.apache.james:james-server","ecosystem":"Maven","purl":"pkg:maven/org.apache.james/james-server"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.6.2"}]}],"versions":["3.0-M1","3.0-M2","3.0-beta2","3.0-beta3","3.0-beta4","3.0.0","3.0.0-RC1","3.0.0-beta5","3.0.1","3.1.0","3.2.0","3.3.0","3.4.0","3.5.0","3.6.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/02/GHSA-v84g-cf5j-xjqx/GHSA-v84g-cf5j-xjqx.json"}}],"schema_version":"1.9.0"}