Improper Neutralization of Special Elements in Output Used by a Downstream Component in nodemailer - CVE-2020-7769

 

Improper Neutralization of Special Elements in Output Used by a Downstream Component in nodemailer - CVE-2020-7769

Published: June 6, 2023


Vulnerability identifier: #VU76973
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-7769
CWE-ID: CWE-74
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to use of crafted recipient email addresses. A remote unauthenticated attacker can trigger the vulnerability resulting in arbitrary command flag injection in sendmail transport for sending mails.


Affected software

nodemailer
IBM Integration Bus
IBM Cloud Automation Manager
IBM App Connect Enterprise

How to mitigate CVE-2020-7769

Install updates from vendor's website.

nodemailer - update to 6.4.16
IBM Cloud Automation Manager - update to 4.2.0.1 iFix 2
IBM App Connect Enterprise - update to 11.0.0.11

External References

Related Security Bulletins