- Description
- A flaw was found in Nodemailer. This vulnerability allows a denial of service (DoS) via a crafted email address header that triggers infinite recursion in the address parser.
- Source
- secalert@redhat.com
- NVD status
- Modified
- Products
- nodemailer, advanced_cluster_management_for_kubernetes, ceph_storage, developer_hub
CVSS 3.1
- Type
- Primary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity
- HIGH
- secalert@redhat.com
- CWE-703
- Hype score
- Not currently trending
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nodemailer:nodemailer:*:*:*:*:*:node.js:*:*",
"matchCriteriaId": "3ABBB33C-621B-4520-99B8-1C687484F816",
"versionEndExcluding": "7.0.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:redhat:advanced_cluster_management_for_kubernetes:2.0:*:*:*:*:*:*:*",
"matchCriteriaId": "4B0E6B4B-BAA6-474E-A18C-72C9719CEC1F",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:redhat:ceph_storage:8.0:*:*:*:*:*:*:*",
"matchCriteriaId": "52AE9D9D-5D74-4AB8-8FF9-5CEA2A1A97B8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:redhat:developer_hub:-:*:*:*:*:*:*:*",
"matchCriteriaId": "C64C29AF-F32F-4AC1-BC84-276B4024D0C5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]