The submission service in Dovecot before 2.3.15 allows STARTTLS command injection in lib-smtp. Sensitive information can be redirected to an attacker-controlled address.
References
Configurations
History
No history.
Information
Published : 2021-06-28 13:15
Updated : 2024-11-21 06:08
NVD link : CVE-2021-33515
Mitre link : CVE-2021-33515
CVE.ORG link : CVE-2021-33515
JSON object : View
Products Affected
fedoraproject
- fedora
debian
- debian_linux
dovecot
- dovecot
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')