CRITICAL
Command Injection
Published Nov 12, 2020
9.8
CRITICALCVSS 3.1
EPSS 2.30%
Description
This affects the package nodemailer before 6.4.16. Use of crafted recipient email addresses may result in arbitrary command flag injection in sendmail transport for sending mails.
Affected products
- Vendor n/a Product Nodemailer Defaultn/a
- Version unspecifiedStatusaffectedConstraints<6.4.16
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Nodemailer | n/a |
|
- < 6.4.16
No data.
No Red Hat product state for this CVE.
nodemailer
npm
Introduced 0 Fixed 6.4.16
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | nodemailer | 0 | 6.4.16 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- https://github.com/advisories/GHSA-48ww-j4fc-435p Advisory
- https://github.com/nodemailer/nodemailer/blob/33b62e2ea6bc9215c99a9bb4bfba94e2fb27ebd0/lib/sendmail-transport/index.js#L75
- https://github.com/nodemailer/nodemailer/blob/33b62e2ea6bc9215c99a9bb4bfba94e2fb27ebd0/lib/sendmail-transport/index.js%23L75 x_refsource_MISCBroken LinkThird Party Advisory
- https://github.com/nodemailer/nodemailer/commit/ba31c64c910d884579875c52d57ac45acc47aa54 x_refsource_MISCPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-7769
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1039742 x_refsource_MISCExploitPatchThird Party Advisory
- https://snyk.io/vuln/SNYK-JS-NODEMAILER-1038834 x_refsource_MISCExploitPatchThird Party Advisory
- https://www.npmjs.com/package/nodemailer
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-48ww-j4fc-435p | Advisory | |
| https://github.com/nodemailer/nodemailer/blob/33b62e2ea6bc9215c99a9bb4bfba94e2fb27ebd0/lib/sendmail-transport/index.js#L75 | ||
| https://github.com/nodemailer/nodemailer/blob/33b62e2ea6bc9215c99a9bb4bfba94e2fb27ebd0/lib/sendmail-transport/index.js%23L75 | x_refsource_MISCBroken LinkThird Party Advisory | |
| https://github.com/nodemailer/nodemailer/commit/ba31c64c910d884579875c52d57ac45acc47aa54 | x_refsource_MISCPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-7769 | ||
| https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1039742 | x_refsource_MISCExploitPatchThird Party Advisory | |
| https://snyk.io/vuln/SNYK-JS-NODEMAILER-1038834 | x_refsource_MISCExploitPatchThird Party Advisory | |
| https://www.npmjs.com/package/nodemailer |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner snyk
Published Nov 12, 2020
Updated Sep 16, 2024
Reserved Jan 21, 2020
Link CVE-2020-7769
CISA Vulnrichment
GHSA-48WW-J4FC-435P Updated n/a