Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v7cm-w955-pj6g

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Improper Input Validation Apache Commons Email

If a user of Apache Commons Email (typically an application programmer) passes unvalidated input as the so-called "Bounce Address", and that input contains line-breaks, then the email details (recipients, contents, etc.) might be manipulated. Mitigation: Users should upgrade to Commons-Email 1.5. You can mitigate this vulnerability for older versions of Commons Email by stripping line-breaks from data, that will be passed to Email.setBounceAddress(String).

Пакеты

Наименование

org.apache.commons:commons-email

maven
Затронутые версииВерсия исправления

< 1.5

1.5

EPSS

Процентиль: 77%
0.00996
Низкий

7.5 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 8 лет назад

If a user of Apache Commons Email (typically an application programmer) passes unvalidated input as the so-called "Bounce Address", and that input contains line-breaks, then the email details (recipients, contents, etc.) might be manipulated. Mitigation: Users should upgrade to Commons-Email 1.5. You can mitigate this vulnerability for older versions of Commons Email by stripping line-breaks from data, that will be passed to Email.setBounceAddress(String).

CVSS3: 7.5
nvd
почти 8 лет назад

If a user of Apache Commons Email (typically an application programmer) passes unvalidated input as the so-called "Bounce Address", and that input contains line-breaks, then the email details (recipients, contents, etc.) might be manipulated. Mitigation: Users should upgrade to Commons-Email 1.5. You can mitigate this vulnerability for older versions of Commons Email by stripping line-breaks from data, that will be passed to Email.setBounceAddress(String).

CVSS3: 7.5
debian
почти 8 лет назад

If a user of Apache Commons Email (typically an application programmer ...

suse-cvrf
около 8 лет назад

Security update for apache-commons-email

EPSS

Процентиль: 77%
0.00996
Низкий

7.5 High

CVSS3

Дефекты

CWE-20