PT-2021-24466 · Unknown+1 · Nodemailer+1

Published

2021-09-20

·

Updated

2021-09-20

CVSS v3.1

5.8

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Ghost versions prior to 4.15.0
Description: The issue affects sites using the sendmail transport as part of their mail config, making them vulnerable to remote command injection due to a problem in the nodemailer dependency. Ghost defaults to the direct transport, so this is only exploitable if the sendmail transport is explicitly used.
Recommendations: For versions prior to 4.15.0, upgrade to version 4.15.0 as soon as possible. As a temporary workaround, consider using an alternative email transport as described in the documentation.

Fix

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-WFRJ-QQC2-83CM

Affected Products

Ghost
Nodemailer