The lettre library through 0.10.0-alpha for Rust allows arbitrary sendmail option injection via transport/sendmail/mod.rs.
References
Link | Resource |
---|---|
https://github.com/lettre/lettre | Product Third Party Advisory |
https://github.com/RustSec/advisory-db/pull/478/files | Patch Third Party Advisory |
https://rustsec.org/advisories/RUSTSEC-2020-0069.html | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2020-11-12 10:15
Updated : 2021-01-28 17:00
NVD link : CVE-2020-28247
Mitre link : CVE-2020-28247
JSON object : View
CWE
Products Affected
lettre
- lettre