PT-2021-4091 · Unknown · Nodemailer
Adam Williams
·
Published
2021-05-23
·
Updated
2021-12-10
·
CVE-2021-23400
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Nodemailer versions prior to 6.6.1
Description
The issue is related to insufficient neutralization of newline and carriage return characters in requests, which can lead to HTTP Header Injection. This could allow a remote attacker to access confidential data, compromise data integrity, and cause a denial of service. The vulnerability occurs when unsanitized user input that may contain newlines and carriage returns is passed into an address object.
Recommendations
For versions prior to 6.6.1, update to version 6.6.1 or later to resolve the issue. As a temporary workaround, consider sanitizing user input to prevent the inclusion of newline and carriage return characters in address objects. Restrict access to sensitive data and monitor for potential exploitation attempts.
Exploit
Fix
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nodemailer