Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-7769

Опубликовано: 12 нояб. 2020
Источник: debian
EPSS Низкий

Описание

This affects the package nodemailer before 6.4.16. Use of crafted recipient email addresses may result in arbitrary command flag injection in sendmail transport for sending mails.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-nodemailerfixed6.4.16-1package

Примечания

  • https://snyk.io/vuln/SNYK-JS-NODEMAILER-1038834

  • https://github.com/nodemailer/nodemailer/commit/ba31c64c910d884579875c52d57ac45acc47aa54

EPSS

Процентиль: 82%
0.02284
Низкий

Связанные уязвимости

CVSS3: 8.6
ubuntu
почти 6 лет назад

This affects the package nodemailer before 6.4.16. Use of crafted recipient email addresses may result in arbitrary command flag injection in sendmail transport for sending mails.

CVSS3: 8.6
nvd
почти 6 лет назад

This affects the package nodemailer before 6.4.16. Use of crafted recipient email addresses may result in arbitrary command flag injection in sendmail transport for sending mails.

CVSS3: 9.8
github
больше 5 лет назад

Command injection in nodemailer

EPSS

Процентиль: 82%
0.02284
Низкий