SB2021092004 - Multiple vulnerabilities in Ghost
Published: September 20, 2021 Updated: April 27, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 vulnerabilities.
1) Command Injection (CVE-ID: N/A)
CWE-ID: CWE-77 - Command injection
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
The vulnerability allows a remote attacker to execute arbitrary commands on the target system.
The vulnerability exists due to improper input validation when using sendmail email transport. A remote unauthenticated attacker can pass specially crafted data to the application and execute arbitrary commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
2) Command injection (CVE-ID: N/A)
CWE-ID: CWE-77 - Command injection
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
The vulnerability allows a remote attacker to inject commands.
The vulnerability exists due to command injection in the sendmail email transport configuration when using the sendmail transport for mail delivery. A remote attacker can trigger the vulnerable nodemailer sendmail handling to inject commands.
Only sites explicitly configured to use the sendmail transport are vulnerable.
Remediation
Install update from vendor's website.