SMTP Injection Affecting mail package, versions < 2.5.5


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.35% (72nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-RUBY-MAIL-20244
  • published8 Dec 2015
  • disclosed8 Dec 2015
  • creditTakeshi Terada

Introduced: 8 Dec 2015

CVE-2015-9097  (opens in a new tab)
CWE-74  (opens in a new tab)

Overview

mail is a Ruby Mail handler gem.

Affected versions of this gem do not validate or impose a length limit on email address fields. This means that an attacker can modify messages sent with the gem via a specially-crafted recipient email address.

Note:

  1. Applications that validate email address format are not affected by this vulnerability.

  2. Applications considered vulnerable:

    • Use mail, versions <2.5.5 on Ruby <2.4.0
    • All net/smtp users on Ruby <2.4.0 (See CVE-2015-9096)

CVSS Scores

version 3.1