VYPR
Medium severity5.3NVD Advisory· Published Nov 12, 2020· Updated Jun 17, 2026

CVE-2020-28247

CVE-2020-28247

Description

The lettre library through 0.10.0-alpha for Rust allows arbitrary sendmail option injection via transport/sendmail/mod.rs.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
lettrecrates.io
>= 0.9.0, < 0.9.50.9.5
lettrecrates.io
>= 0.8.0, < 0.8.40.8.4
lettrecrates.io
>= 0.7.0, < 0.7.10.7.1

Affected products

7
  • Rust/lettre librarydescription
  • Lettre/Lettre5 versions
    cpe:2.3:a:lettre:lettre:*:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:lettre:lettre:*:*:*:*:*:*:*:*range: >=0.8.0,<=0.8.3
    • cpe:2.3:a:lettre:lettre:0.7.0:*:*:*:*:*:*:*
    • cpe:2.3:a:lettre:lettre:0.10.0:alpha1:*:*:*:*:*:*
    • cpe:2.3:a:lettre:lettre:0.10.0:alpha2:*:*:*:*:*:*
    • cpe:2.3:a:lettre:lettre:0.10.0:alpha3:*:*:*:*:*:*
  • ghsa-coords
    Range: >= 0.9.0, < 0.9.5

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.