Vulnerability CVE-2021-23400


Published: 2021-06-29

Description:
The package nodemailer before 6.6.1 are vulnerable to HTTP Header Injection if unsanitized user input that may contain newlines and carriage returns is passed into an address object.

Type:

CWE-74

CVSS2 => (AV:N/AC:M/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.8/10
6.4/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Nodemailer -> Nodemailer 

 References:
https://snyk.io/vuln/SNYK-JS-NODEMAILER-1296415
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1314737
https://github.com/nodemailer/nodemailer/commit/7e02648cc8cd863f5085bad3cd09087bccf84b9f
https://github.com/nodemailer/nodemailer/issues/1289

Copyright 2024, cxsecurity.com

 

Back to Top