In Jakarta Mail 2.0.2 it is possible to preform a SMTP Injection by utilizing the \r and \n UTF-8 characters to separate different messages.
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as input terminators when they are sent to a downstream component.
Link | Tags |
---|---|
https://gitlab.eclipse.org/security/cve-assignement/-/issues/67 | issue tracking third party advisory |