The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is identified as the value of the addr-spec. In some applications, an attacker can bypass a protection mechanism in which application access is granted only after verifying receipt of e-mail to a specific domain (e.g., only @company.example.com addresses may be used for signup). This occurs in email/_parseaddr.py in recent versions of Python.
Metrics
Affected Vendors & Products
References
History
Mon, 19 May 2025 13:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Fedoraproject
Fedoraproject fedora Netapp Netapp active Iq Unified Manager Netapp ontap Select Deploy Administration Utility |
|
CPEs | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:* cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:* cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* |
|
Vendors & Products |
Fedoraproject
Fedoraproject fedora Netapp Netapp active Iq Unified Manager Netapp ontap Select Deploy Administration Utility |
Fri, 22 Nov 2024 12:00:00 +0000

Status: PUBLISHED
Assigner: mitre
Published: 2023-04-18T00:00:00
Updated: 2024-08-02T12:01:32.288Z
Reserved: 2023-02-27T00:00:00
Link: CVE-2023-27043

No data.

Status : Analyzed
Published: 2023-04-19T00:15:07.973
Modified: 2025-05-19T12:38:20.773
Link: CVE-2023-27043
