Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 6

Количество 6

ubuntu логотип

CVE-2026-47242

около 1 месяца назад

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, when Net::IMAP#id is called with a hash argument, although the ID field value strings are correctly quoted (escaping quoted specials), they were not validated to prohibit CRLF sequences. While Net::IMAP#enable does process its arguments for aliases, it does not validate them as valid atoms (or as a list of valid atoms). The #to_s value is sent verbatim. Arguments to either command could be used by an attacker to inject arbitrary IMAP commands. This vulnerability is fixed in 0.6.5 and 0.5.15.

EPSS: Низкий
nvd логотип

CVE-2026-47242

около 1 месяца назад

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, when Net::IMAP#id is called with a hash argument, although the ID field value strings are correctly quoted (escaping quoted specials), they were not validated to prohibit CRLF sequences. While Net::IMAP#enable does process its arguments for aliases, it does not validate them as valid atoms (or as a list of valid atoms). The #to_s value is sent verbatim. Arguments to either command could be used by an attacker to inject arbitrary IMAP commands. This vulnerability is fixed in 0.6.5 and 0.5.15.

EPSS: Низкий
msrc логотип

CVE-2026-47242

около 1 месяца назад

Net::IMAP: Command Injection via ID command argument

EPSS: Низкий
debian логотип

CVE-2026-47242

около 1 месяца назад

Net::IMAP implements Internet Message Access Protocol (IMAP) client fu ...

EPSS: Низкий
github логотип

GHSA-46q3-7gv7-qmgg

около 2 месяцев назад

Net::IMAP: Command Injection via ID command argument

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3090-1

19 дней назад

Security update for ruby3.4

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-47242

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, when Net::IMAP#id is called with a hash argument, although the ID field value strings are correctly quoted (escaping quoted specials), they were not validated to prohibit CRLF sequences. While Net::IMAP#enable does process its arguments for aliases, it does not validate them as valid atoms (or as a list of valid atoms). The #to_s value is sent verbatim. Arguments to either command could be used by an attacker to inject arbitrary IMAP commands. This vulnerability is fixed in 0.6.5 and 0.5.15.

0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-47242

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, when Net::IMAP#id is called with a hash argument, although the ID field value strings are correctly quoted (escaping quoted specials), they were not validated to prohibit CRLF sequences. While Net::IMAP#enable does process its arguments for aliases, it does not validate them as valid atoms (or as a list of valid atoms). The #to_s value is sent verbatim. Arguments to either command could be used by an attacker to inject arbitrary IMAP commands. This vulnerability is fixed in 0.6.5 and 0.5.15.

0%
Низкий
около 1 месяца назад
msrc логотип
CVE-2026-47242

Net::IMAP: Command Injection via ID command argument

0%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-47242

Net::IMAP implements Internet Message Access Protocol (IMAP) client fu ...

0%
Низкий
около 1 месяца назад
github логотип
GHSA-46q3-7gv7-qmgg

Net::IMAP: Command Injection via ID command argument

0%
Низкий
около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:3090-1

Security update for ruby3.4

19 дней назад

Уязвимостей на страницу