The e-mail module of Python 0 - 2.7.18, 3.x - 3.11...
Unreviewed PublishedApr 19, 2023 to the GitHub Advisory Database • UpdatedMar 5, 2024
Description
The e-mail module of Python 0 - 2.7.18, 3.x - 3.11 incorrectly parses e-mail addresses which contain a special character. This vulnerability allows attackers to send messages from e-ail addresses that would otherwise be rejected.
References
Published by theNational Vulnerability DatabaseApr 19, 2023
Published to the GitHub Advisory DatabaseApr 19, 2023
Last updatedMar 5, 2024
Severity
Moderate / 10
CVSS v3 base metrics
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS score
(26th percentile)
Weaknesses
WeaknessCWE-20
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.Learn more on MITRE.CVE ID
CVE-2023-27043
GHSA ID
GHSA-5mwm-wccq-xqcp
Source code
No known source code
Dependabot alerts are not supported on this advisory because it does not have a package from a supported ecosystem with an affected and fixed version.
LoadingChecking history
Uh oh!
There was an error while loading.Please reload this page.
See something to contribute?Suggest improvements for this vulnerability.