SMTP Header Injection Affecting org.apache.commons:commons-email Open this link in a new tab package, versions [,1.5)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.Test your applications
31 Aug 2017
31 Jul 2017
How to fix?
org.apache.commons:commons-email to version 1.5 or higher.
org.apache.commons:commons-email aims to provide a API for sending email.
Affected versions of the package are vulnerable to SMTP Header Injection. When a call-site passes a subject for an email that contains line-breaks in Apache Commons Email 1.0 through 1.4, the caller can add arbitrary SMTP headers.