You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
It is possible to set a subject which contains newlines and custom SMTP protocol directives which directly sets the body of the email. This can be an issue when the subject comes from an external resource.
As a matter of precaution, Simple Java Mail should simply remove newline characters from all values (except for the body).
bbottema
changed the title
Subject property (and possible others) can be abused for injection attacks
Safeguard subject property (and others) against SMTP CRLF injection attacks
Aug 12, 2017
It is possible to set a subject which contains newlines and custom SMTP protocol directives which directly sets the body of the email. This can be an issue when the subject comes from an external resource.
As a matter of precaution, Simple Java Mail should simply remove newline characters from all values (except for the body).
Also see:
The text was updated successfully, but these errors were encountered: