
Cloud Vulnerability DB
A community-led vulnerabilities database
The lettre library through version 0.10.0-alpha for Rust contains a security vulnerability identified as RUSTSEC-2020-0069 (CVE-2020-28247). The vulnerability was discovered and disclosed in November 2020, affecting the sendmail transport module of the lettre library. This security issue allows attackers to perform arbitrary sendmail option injection through the transport/sendmail/mod.rs component (RustSec Advisory).
The vulnerability has been assigned a CVSS v3.1 base score of 5.3 (MEDIUM) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N. The issue specifically relates to the handling of sendmail command options in the transport module, where insufficient validation of input parameters could lead to command injection (NVD Database).
The vulnerability allows attackers to inject arbitrary sendmail options through the transport/sendmail/mod.rs component, potentially leading to unauthorized manipulation of email sending parameters. The CVSS scoring indicates that while the vulnerability has network accessibility, it primarily affects the integrity of the system with limited impact (NVD Database).
The vulnerability is exploitable remotely with low attack complexity and requires no privileges or user interaction. This makes it relatively straightforward to exploit in environments where the affected versions of the lettre library are in use (NVD Database).
A fix has been implemented through a pull request that improves the sendmail command handling by stopping argument parsing before destination addresses and capturing sendmail stderr for better error handling (Lettre Github).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."