The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade org.webjars.npm:nodemailer to version 9.1.0 or higher.
org.webjars.npm:nodemailer is an Easy as cake e-mail sending from your Node.js applications
Affected versions of this package are vulnerable to Interpretation Conflict via RFC 5322 comment mis-parsing in lib/addressparser/index.js. An attacker can make mail be delivered to an attacker-controlled domain by supplying a recipient such as user@good-corp.com(x)evil.com, which the parser glues into good-corp.comevil.com instead of treating the comment as folding whitespace. Applications that approve recipients by parsing or matching the domain separately can be tricked into sending mail to a domain they never intended to allow, exposing messages to the attacker-controlled recipient.