Apache James server: Temporary File Information Disclosure
Published Jan 6, 2023
5.5
MEDIUMCVSS 3.1
EPSS 0.36%
Description
Usage of temporary files with insecure permissions by the Apache James server allows an attacker with local access to access private user data in transit.
Vulnerable components includes the SMTP stack and IMAP APPEND command.
This issue affects Apache James server version 3.7.2 and prior versions.
Affected products
-
- Version 0StatusaffectedConstraints<=3.7.2
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache James server | unaffected |
|
No data.
Red Hat Data Grid 8
apache-james
Not affected
Red Hat Decision Manager 7
apache-james
Not affected
Red Hat Fuse 7
apache-james
Not affected
Red Hat Integration Camel K 1
apache-james
Not affected
Red Hat Integration Camel Quarkus 1
apache-james
Not affected
Red Hat JBoss Data Grid 7
apache-james
Not affected
Red Hat JBoss Data Virtualization 6
apache-james
Not affected
Red Hat JBoss Enterprise Application Platform 6
apache-james
Not affected
Red Hat JBoss Enterprise Application Platform 7
apache-james
Not affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
apache-james
Not affected
Red Hat JBoss Fuse 6
apache-james
Not affected
Red Hat JBoss Fuse Service Works 6
apache-james
Not affected
Red Hat OpenShift Application Runtimes
apache-james
Not affected
Red Hat Process Automation 7
apache-james
Not affected
Red Hat Satellite 6
apache-james
Not affected
Red Hat Single Sign-On 7
apache-james
Not affected
Red Hat build of Apache Camel for Spring Boot 3
apache-james
Not affected
Red Hat build of Apicurio Registry 2
apache-james
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Data Grid 8 | apache-james | Not affected | n/a |
| Red Hat Decision Manager 7 | apache-james | Not affected | n/a |
| Red Hat Fuse 7 | apache-james | Not affected | n/a |
| Red Hat Integration Camel K 1 | apache-james | Not affected | n/a |
| Red Hat Integration Camel Quarkus 1 | apache-james | Not affected | n/a |
| Red Hat JBoss Data Grid 7 | apache-james | Not affected | n/a |
| Red Hat JBoss Data Virtualization 6 | apache-james | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | apache-james | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | apache-james | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | apache-james | Not affected | n/a |
| Red Hat JBoss Fuse 6 | apache-james | Not affected | n/a |
| Red Hat JBoss Fuse Service Works 6 | apache-james | Not affected | n/a |
| Red Hat OpenShift Application Runtimes | apache-james | Not affected | n/a |
| Red Hat Process Automation 7 | apache-james | Not affected | n/a |
| Red Hat Satellite 6 | apache-james | Not affected | n/a |
| Red Hat Single Sign-On 7 | apache-james | Not affected | n/a |
| Red Hat build of Apache Camel for Spring Boot 3 | apache-james | Not affected | n/a |
| Red Hat build of Apicurio Registry 2 | apache-james | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (8)
- https://access.redhat.com/security/cve/CVE-2022-45935 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2158908 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-0555 Advisory
- https://github.com/advisories/GHSA-v6vp-62vc-84qw Advisory
- https://github.com/apache/james-project/commit/b5580d13d6c74ecbf647127eff1a3ac1086f5493
- https://lists.apache.org/thread/j61fo8xc1rxtofrn8vc33whx35s9cj1d vendor-advisoryMailing ListVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-45935
- https://www.cve.org/CVERecord?id=CVE-2022-45935
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-45935 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2158908 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-0555 | Advisory | |
| https://github.com/advisories/GHSA-v6vp-62vc-84qw | Advisory | |
| https://github.com/apache/james-project/commit/b5580d13d6c74ecbf647127eff1a3ac1086f5493 | ||
| https://lists.apache.org/thread/j61fo8xc1rxtofrn8vc33whx35s9cj1d | vendor-advisoryMailing ListVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-45935 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-45935 |
Change history (0)
No recorded changes yet.