SMTP Header Injection Vulnerability in Apache Commons Email by Apache
CVE-2017-9801
7.5HIGH
What is CVE-2017-9801?
This vulnerability in Apache Commons Email versions 1.0 to 1.4 allows an attacker to inject arbitrary SMTP headers by exploiting line breaks in the email subject. When a call-site passes a subject containing line breaks, it can alter the email structure and introduce harmful headers, potentially leading to unauthorized actions, spam, or information leakage.
Affected Version(s)
Apache Commons Email 1.0 to 1.4