CVE-2017-9801

When a call-site passes a subject for an email that contains line-breaks in Apache Commons Email 1.0 through 1.4, the caller can add arbitrary SMTP headers.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:commons_email:1.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:commons_email:1.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:commons_email:1.2:*:*:*:*:*:*:*
cpe:2.3:a:apache:commons_email:1.3:*:*:*:*:*:*:*
cpe:2.3:a:apache:commons_email:1.3.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:commons_email:1.3.2:*:*:*:*:*:*:*
cpe:2.3:a:apache:commons_email:1.3.3:*:*:*:*:*:*:*
cpe:2.3:a:apache:commons_email:1.4:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-08-07 15:29

Updated : 2024-02-04 19:29


NVD link : CVE-2017-9801

Mitre link : CVE-2017-9801

CVE.ORG link : CVE-2017-9801


JSON object : View

Products Affected

apache

  • commons_email
CWE
CWE-20

Improper Input Validation