CVE-2021-23400

MEDIUM6.3EPSS 0.54%

Header injection in nodemailer

發布日:2021/12/10修改日:2025/1/14

描述

The package nodemailer before 6.6.1 are vulnerable to HTTP Header Injection if unsanitized user input that may contain newlines and carriage returns is passed into an address object.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM6.3CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

參考連結(6)