CVE-2017-9801

When a call-site passes a subject for an email that contains line-breaks in Apache Commons Email 1.0 through 1.4, the caller can add arbitrary SMTP headers.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:commons_email:1.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:commons_email:1.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:commons_email:1.2:*:*:*:*:*:*:*
cpe:2.3:a:apache:commons_email:1.3:*:*:*:*:*:*:*
cpe:2.3:a:apache:commons_email:1.3.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:commons_email:1.3.2:*:*:*:*:*:*:*
cpe:2.3:a:apache:commons_email:1.3.3:*:*:*:*:*:*:*
cpe:2.3:a:apache:commons_email:1.4:*:*:*:*:*:*:*

History

07 Nov 2023, 02:50

Type Values Removed Values Added
References
  • {'url': 'https://lists.apache.org/thread.html/7ef903a772a2ff08605df1be819044fb15df2815eb3d63878b3fbbb5@%3Cannounce.apache.org%3E', 'name': '[announce@apache.org] 20170801 CVE-2017-9801: Apache Commons Email SMTP header injection vulnerabilty', 'tags': ['Patch', 'Vendor Advisory'], 'refsource': 'MLIST'}
  • () https://lists.apache.org/thread.html/7ef903a772a2ff08605df1be819044fb15df2815eb3d63878b3fbbb5%40%3Cannounce.apache.org%3E -

Information

Published : 2017-08-07 15:29

Updated : 2024-02-28 16:04


NVD link : CVE-2017-9801

Mitre link : CVE-2017-9801

CVE.ORG link : CVE-2017-9801


JSON object : View

Products Affected

apache

  • commons_email
CWE
CWE-20

Improper Input Validation