-
Type:
Bug Report
-
Resolution: Fixed
-
Priority:
L3 - Default
-
Affects Version/s: 7.8.0-alpha4
-
Component/s: None
-
None
OWASP scan of Camunda shows a known vulnerability in the commons-email version used in Camunda
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-9801
When a call-site passes a subject for an email that contains line-breaks in Apache Commons Email 1.0 through 1.4, the caller can add arbitrary SMTP headers.