SB2021092004 - Multiple vulnerabilities in Ghost



SB2021092004 - Multiple vulnerabilities in Ghost

Published: September 20, 2021 Updated: April 27, 2026

Security Bulletin ID SB2021092004
CSH Severity
High
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 50% Medium 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 vulnerabilities.


1) Command Injection (CVE-ID: N/A)

CWE-ID: CWE-77 - Command injection

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary commands on the target system.

The vulnerability exists due to improper input validation when using sendmail email transport. A remote unauthenticated attacker can pass specially crafted data to the application and execute arbitrary commands on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


2) Command injection (CVE-ID: N/A)

CWE-ID: CWE-77 - Command injection

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to inject commands.

The vulnerability exists due to command injection in the sendmail email transport configuration when using the sendmail transport for mail delivery. A remote attacker can trigger the vulnerable nodemailer sendmail handling to inject commands.

Only sites explicitly configured to use the sendmail transport are vulnerable.


Remediation

Install update from vendor's website.