Vulnerability

CVE-2024-21742
CVSS Score 5.3 medium

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CWE

CWE-20

[CVE-2024-21742] CWE-20: Improper Input Validation

Description

Improper input validation allows for header injection in MIME4J library when using MIME4J DOM for composing message. This can be exploited by an attacker to add unintended headers to MIME messages.

See org.apache.james/apache-mime4j-core package information