QID 981871
QID 981871: Nodejs (npm) Security Update for nodemailer (GHSA-48ww-j4fc-435p)
This affects the package nodemailer before 6.4.16. Use of crafted recipient email addresses may result in arbitrary command flag injection in sendmail transport for sending mails.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-48ww-j4fc-435p for updates pertaining to this vulnerability.
Vendor References
- GHSA-48ww-j4fc-435p -
github.com/advisories/GHSA-48ww-j4fc-435p
CVEs related to QID 981871
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-48ww-j4fc-435p | nodemailer |
|