Опубликовано: 12 нояб. 2020
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5
CVSS3: 8.6
Описание
This affects the package nodemailer before 6.4.16. Use of crafted recipient email addresses may result in arbitrary command flag injection in sendmail transport for sending mails.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | DNE | |
| devel | not-affected | 6.4.16-1 |
| esm-apps/focal | needed | |
| esm-apps/jammy | not-affected | 6.4.16-1 |
| esm-apps/noble | not-affected | 6.4.16-1 |
| esm-apps/resolute | not-affected | 6.4.16-1 |
| esm-infra-legacy/trusty | DNE | |
| focal | ignored | end of standard support, was needed |
| groovy | ignored | end of life |
| hirsute | not-affected | 6.4.16-1 |
Показывать по
10
Ссылки на источники
EPSS
Процентиль: 82%
0.02284
Низкий
7.5 High
CVSS2
8.6 High
CVSS3
Связанные уязвимости
CVSS3: 8.6
nvd
почти 6 лет назад
This affects the package nodemailer before 6.4.16. Use of crafted recipient email addresses may result in arbitrary command flag injection in sendmail transport for sending mails.
CVSS3: 8.6
debian
почти 6 лет назад
This affects the package nodemailer before 6.4.16. Use of crafted reci ...
EPSS
Процентиль: 82%
0.02284
Низкий
7.5 High
CVSS2
8.6 High
CVSS3