Описание
This affects the package nodemailer before 6.4.16. Use of crafted recipient email addresses may result in arbitrary command flag injection in sendmail transport for sending mails.
Ссылки
- Broken LinkThird Party Advisory
- PatchThird Party Advisory
- ExploitPatchThird Party Advisory
- ExploitPatchThird Party Advisory
- Broken LinkThird Party Advisory
- PatchThird Party Advisory
- ExploitPatchThird Party Advisory
- ExploitPatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 6.4.16 (исключая)
cpe:2.3:a:nodemailer:nodemailer:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 66%
0.00509
Низкий
8.6 High
CVSS3
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-88
Связанные уязвимости
CVSS3: 8.6
ubuntu
около 5 лет назад
This affects the package nodemailer before 6.4.16. Use of crafted recipient email addresses may result in arbitrary command flag injection in sendmail transport for sending mails.
CVSS3: 8.6
debian
около 5 лет назад
This affects the package nodemailer before 6.4.16. Use of crafted reci ...
EPSS
Процентиль: 66%
0.00509
Низкий
8.6 High
CVSS3
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-88