CVE-2020-7769: Command Injection
Published Nov 12, 2020
·Updated
This affects the package nodemailer before 6.4.16. Use of crafted recipient email addresses may result in arbitrary command flag injection in sendmail transport for sending mails.
Affected Software
1 affected component
Nodemailer Nodemailer Node.js<6.4.16
Remediation
Patch Available
Patch Available
Event History
Nov 12, 2020
CVE Published
via MITRE·08:30 AM
Data Sourced
via MITRE·08:30 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-7769?
CVE-2020-7769 is classified with a moderate severity level due to potential command injection vulnerabilities.
2
What software versions are affected by CVE-2020-7769?
CVE-2020-7769 affects all versions of Nodemailer prior to 6.4.16.
3
What is the impact of CVE-2020-7769?
CVE-2020-7769 may allow attackers to inject arbitrary command flags via crafted recipient email addresses when using the sendmail transport.
4
How do I fix CVE-2020-7769?
To fix CVE-2020-7769, update Nodemailer to version 6.4.16 or later.
5
Are there any workarounds for CVE-2020-7769?
There are no specific workarounds for CVE-2020-7769; updating to the latest version is recommended for protection.