Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The mail gem before 2.5.5 for Ruby (aka A Really Ruby Mail Library) is vulnerable to SMTP command injection via CRLF sequences in a RCPT TO or MAIL FROM command, as demonstrated by CRLF sequences immediately before and after a DATA substring.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Ruby mail gem 命令注入漏洞
Vulnerability Description
Ruby是日本软件开发者松本行弘所研发的一种跨平台、面向对象的动态类型编程语言。mail gem是其中的一个电子邮件处理库。 Ruby mail gem 2.5.5之前的版本中存在命令注入漏洞。攻击者可借助RCPT TO或MAIL FROM命令中的CRLF序列利用该漏洞修改使用gem发送的消息。
CVSS Information
N/A
Vulnerability Type
N/A