Lack of data validation In node-nodemailer
Description
Header injection in nodemailer The package nodemailer before 6.6.1 are vulnerable to HTTP Header Injection if unsanitized user input that may contain newlines and carriage returns is passed into an address object.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 11 | 6.4.17-3 | ||
debian 14 | 6.4.17-3 | ||
npm | 6.6.1 | ||
debian 13 | 6.4.17-3 | ||
debian 12 | 6.4.17-3 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2.