PT-2021-24466 · Unknown+1 · Nodemailer+1
Published
2021-09-20
·
Updated
2021-09-20
CVSS v3.1
5.8
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Ghost versions prior to 4.15.0
Description:
The issue affects sites using the
sendmail transport as part of their mail config, making them vulnerable to remote command injection due to a problem in the nodemailer dependency. Ghost defaults to the direct transport, so this is only exploitable if the sendmail transport is explicitly used.Recommendations:
For versions prior to 4.15.0, upgrade to version 4.15.0 as soon as possible.
As a temporary workaround, consider using an alternative email transport as described in the documentation.
Fix
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ghost
Nodemailer