Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-7962

Опубликовано: 21 июл. 2025
Источник: debian
EPSS Низкий

Описание

In Jakarta Mail 2.0.2 it is possible to preform a SMTP Injection by utilizing the \r and \n UTF-8 characters to separate different messages.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
jakarta-mailunfixedpackage
jakarta-mailno-dsatrixiepackage
jakarta-mailno-dsabookwormpackage
jakarta-mailpostponedbullseyepackage
javamailunfixedpackage
javamailno-dsatrixiepackage
javamailno-dsabookwormpackage
javamailpostponedbullseyepackage

Примечания

  • https://gitlab.eclipse.org/security/cve-assignement/-/issues/67

  • https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/290

  • https://github.com/jakartaee/mail-api/commit/cc9b954f3816f18f1b96dd50b1f8f51b3116462d (1.6.8)

EPSS

Процентиль: 6%
0.00029
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 месяца назад

In Jakarta Mail 2.0.2 it is possible to preform a SMTP Injection by utilizing the \r and \n UTF-8 characters to separate different messages.

CVSS3: 5.3
redhat
около 1 месяца назад

In Jakarta Mail 2.0.2 it is possible to preform a SMTP Injection by utilizing the \r and \n UTF-8 characters to separate different messages.

CVSS3: 7.5
nvd
около 1 месяца назад

In Jakarta Mail 2.0.2 it is possible to preform a SMTP Injection by utilizing the \r and \n UTF-8 characters to separate different messages.

CVSS3: 7.5
github
около 1 месяца назад

Jakarta Mail vulnerable to SMTP Injection

EPSS

Процентиль: 6%
0.00029
Низкий