textview_uri_security_check in textview.c in Claws Mail before 3.18.0, and Sylpheed through 3.7.0, does not have sufficient link checks before accepting a click.
References
Configurations
History
20 Sep 2021, 12:22
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* |
|
References |
|
09 Aug 2021, 16:32
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://git.claws-mail.org/?p=claws.git;a=commit;h=ac286a71ed78429e16c612161251b9ea90ccd431 - Patch, Vendor Advisory | |
References | (MISC) https://claws-mail.org/download.php?file=releases/claws-mail-3.18.0.tar.xz - Patch, Vendor Advisory | |
References | (MISC) https://sylpheed.sraoss.jp/sylpheed/v3.7/sylpheed-3.7.0.tar.xz - Patch, Third Party Advisory | |
CVSS |
v2 : v3 : |
v2 : 5.8
v3 : 6.1 |
CWE | CWE-601 | |
CPE | cpe:2.3:a:claws-mail:claws-mail:*:*:*:*:*:*:*:* cpe:2.3:a:sylpheed_project:sylpheed:*:*:*:*:*:*:*:* |
30 Jul 2021, 15:16
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-07-30 15:15
Updated : 2024-02-04 21:47
NVD link : CVE-2021-37746
Mitre link : CVE-2021-37746
CVE.ORG link : CVE-2021-37746
JSON object : View
Products Affected
claws-mail
- claws-mail
sylpheed_project
- sylpheed
fedoraproject
- fedora
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')