{"id":"CVE-2018-1294","aliases":[],"url":"https://o3.security/vulnerability/CVE-2018-1294","summary":"Improper Input Validation Apache Commons Email","details":"If a user of Apache Commons Email (typically an application programmer) passes unvalidated input as the so-called \"Bounce Address\", and that input contains line-breaks, then the email details (recipients, contents, etc.) might be manipulated. Mitigation: Users should upgrade to Commons-Email 1.5. You can mitigate this vulnerability for older versions of Commons Email by stripping line-breaks from data, that will be passed to Email.setBounceAddress(String).","published":"2022-05-14T01:28:26Z","modified":"2023-11-08T03:59:51.656421Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.apache.commons:commons-email","fixedVersion":"1.5"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-1294"},{"type":"WEB","url":"http://seclists.org/oss-sec/2018/q1/107"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T03:59:51.656421Z"}}