textview_uri_security_check in textview.c in Claws Mail before 3.18.0, and Sylpheed through 3.7.0, does not have sufficient link checks before accepting a click.
References
Configurations
History
21 Nov 2024, 06:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://claws-mail.org/download.php?file=releases/claws-mail-3.18.0.tar.xz - Patch, Vendor Advisory | |
References | () https://git.claws-mail.org/?p=claws.git%3Ba=commit%3Bh=ac286a71ed78429e16c612161251b9ea90ccd431 - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L2QNUIWASJLPUZZKWICGCEGYJZCQE7NH/ - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RCJXHUSYHGVBSH2ULD7HNXLM7QNRECZ6/ - | |
References | () https://sylpheed.sraoss.jp/sylpheed/v3.7/sylpheed-3.7.0.tar.xz - Patch, Third Party Advisory |
07 Nov 2023, 03:37
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2021-07-30 15:15
Updated : 2024-11-21 06:15
NVD link : CVE-2021-37746
Mitre link : CVE-2021-37746
CVE.ORG link : CVE-2021-37746
JSON object : View
Products Affected
fedoraproject
- fedora
claws-mail
- claws-mail
sylpheed_project
- sylpheed
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')