The package nodemailer before 6.6.1 are vulnerable to HTTP Header Injection if unsanitized user input that may contain newlines and carriage returns is passed into an address object.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: snyk

Published: 2021-06-29T00:00:00

Updated: 2021-06-29T11:45:11

Reserved: 2021-01-08T00:00:00


Link: CVE-2021-23400

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-06-29T12:15:08.363

Modified: 2021-07-06T18:48:29.997


Link: CVE-2021-23400

JSON object: View

cve-icon Redhat Information

No data.

CWE