UBUNTU-CVE-2018-1294
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-1294
Summary:
Details: If a user of Apache Commons Email (typically an application programmer) passes unvalidated input as the so-called "Bounce Address", and that input contains line-breaks, then the email details (recipients, contents, etc.) might be manipulated. Mitigation: Users should upgrade to Commons-Email 1.5. You can mitigate this vulnerability for older versions of Commons Email by stripping line-breaks from data, that will be passed to Email.setBounceAddress(String).
References: https://ubuntu.com/security/CVE-2018-1294, https://marc.info/?i=CAF8HOZ+J3NkaywfbHuQpHxK9ZXeT4=4Vs9rOwCDiUdnt1QA1Yw@mail.gmail.com, https://www.cve.org/CVERecord?id=CVE-2018-1294
Affected packages
Package
Name: commons-email
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=bionic
Affected ranges
Type: ECOSYSTEM
Events:
