Security Advisory

CVE-2017-9801

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2017-08-07 15:00:00
Last updated 2024-09-16 19:05:37
Assigner apache
State PUBLISHED

Description

When a call-site passes a subject for an email that contains line-breaks in Apache Commons Email 1.0 through 1.4, the caller can add arbitrary SMTP headers.