CVE-2021-23400
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
The package nodemailer before 6.6.1 are vulnerable to HTTP Header Injection if unsanitized user input that may contain newlines and carriage returns is passed into an address object.
Affected (1)
Products: Nodemailer: Nodemailer
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 6.6.1 |
References (8)
Source: report@snyk.io
PatchThird Party Advisory
Source: report@snyk.io
ExploitPatchThird Party Advisory
Source: report@snyk.io
ExploitPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatchThird Party Advisory
Timeline
No history available yet.