CVE-2018-1294: Improper Input Validation
(updated )
If a user of Apache Commons Email (typically an application programmer) passes unvalidated input as the Bounce Address
, and the input contains line-breaks, then the email details (recipients, contents, etc.) might be manipulated.
References
Detect and mitigate CVE-2018-1294 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →