Cela affecte le paquet nodemailer avant 6.4.16. L’utilisation d’adresses e-mail du destinataire peut donner lieu à artisanaux injection de drapeau de commande arbitraire dans le transport sendmail pour l’envoi de mails.
https://github.com/nodemailer/nodemailer/blob/33b62e2ea6bc9215c99a9bb4bfba94e2fb27ebd0/lib/sendmail-transport/index.js%23L75
https://github.com/nodemailer/nodemailer/blob/33b62e2ea6bc9215c99a9bb4bfba94e2fb27ebd0/lib/sendmail-transport/index.js%23L75
https://github.com/nodemailer/nodemailer/commit/ba31c64c910d884579875c52d57ac45acc47aa54
https://github.com/nodemailer/nodemailer/commit/ba31c64c910d884579875c52d57ac45acc47aa54
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1039742
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1039742
https://snyk.io/vuln/SNYK-JS-NODEMAILER-1038834
https://snyk.io/vuln/SNYK-JS-NODEMAILER-1038834
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7769