Improper Neutralization of Special Elements in Output Used by a Downstream Component in nodemailer - CVE-2020-7769
Published: June 6, 2023
Vulnerability identifier: #VU76973
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-7769
CWE-ID: CWE-74
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to use of crafted recipient email addresses. A remote unauthenticated attacker can trigger the vulnerability resulting in arbitrary command flag injection in sendmail transport for sending mails.
Affected software
nodemailer
IBM Integration Bus
IBM Cloud Automation Manager
IBM App Connect Enterprise
IBM Integration Bus
IBM Cloud Automation Manager
IBM App Connect Enterprise
How to mitigate CVE-2020-7769
Install updates from vendor's website.
nodemailer - update to 6.4.16
IBM Cloud Automation Manager - update to 4.2.0.1 iFix 2
IBM App Connect Enterprise - update to 11.0.0.11
IBM Cloud Automation Manager - update to 4.2.0.1 iFix 2
IBM App Connect Enterprise - update to 11.0.0.11
External References
- https://snyk.io/vuln/SNYK-JS-NODEMAILER-1038834
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1039742
- https://github.com/nodemailer/nodemailer/blob/33b62e2ea6bc9215c99a9bb4bfba94e2fb27ebd0/lib/sendmail-transport/index.js%23L75
- https://github.com/nodemailer/nodemailer/commit/ba31c64c910d884579875c52d57ac45acc47aa54