PT-2021-4091 · Unknown · Nodemailer

Adam Williams

·

Published

2021-05-23

·

Updated

2021-12-10

·

CVE-2021-23400

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Nodemailer versions prior to 6.6.1
Description The issue is related to insufficient neutralization of newline and carriage return characters in requests, which can lead to HTTP Header Injection. This could allow a remote attacker to access confidential data, compromise data integrity, and cause a denial of service. The vulnerability occurs when unsanitized user input that may contain newlines and carriage returns is passed into an address object.
Recommendations For versions prior to 6.6.1, update to version 6.6.1 or later to resolve the issue. As a temporary workaround, consider sanitizing user input to prevent the inclusion of newline and carriage return characters in address objects. Restrict access to sensitive data and monitor for potential exploitation attempts.

Exploit

Fix

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04670
CVE-2021-23400
GHSA-HWQF-GCQM-7353
SNYK-JAVA-ORGWEBJARSNPM-1314737
SNYK-JS-NODEMAILER-1296415

Affected Products

Nodemailer