Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-1294

Опубликовано: 20 мар. 2018
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

If a user of Apache Commons Email (typically an application programmer) passes unvalidated input as the so-called "Bounce Address", and that input contains line-breaks, then the email details (recipients, contents, etc.) might be manipulated. Mitigation: Users should upgrade to Commons-Email 1.5. You can mitigate this vulnerability for older versions of Commons Email by stripping line-breaks from data, that will be passed to Email.setBounceAddress(String).

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apache:commons_email:*:*:*:*:*:*:*:*
Версия от 1.0 (включая) до 1.4 (включая)

EPSS

Процентиль: 76%
0.00996
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 8 лет назад

If a user of Apache Commons Email (typically an application programmer) passes unvalidated input as the so-called "Bounce Address", and that input contains line-breaks, then the email details (recipients, contents, etc.) might be manipulated. Mitigation: Users should upgrade to Commons-Email 1.5. You can mitigate this vulnerability for older versions of Commons Email by stripping line-breaks from data, that will be passed to Email.setBounceAddress(String).

CVSS3: 7.5
debian
почти 8 лет назад

If a user of Apache Commons Email (typically an application programmer ...

suse-cvrf
около 8 лет назад

Security update for apache-commons-email

CVSS3: 7.5
github
больше 3 лет назад

Improper Input Validation Apache Commons Email

EPSS

Процентиль: 76%
0.00996
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-20