shaggyinsomniac opened a new pull request, #4258:
URL: https://github.com/apache/logging-log4j2/pull/4258

   ## Description
   The `SmtpAppender` subject is produced by a PatternLayout serializer and 
commonly embeds event data (message, MDC, throwable). CR/LF sequences in that 
data currently flow into `MimeMessage.setSubject` unsanitized, allowing mail 
header injection when an attacker can influence logged content — for example a 
logged username or error message containing `\r\nBcc: [email protected]` 
results in an injected `Bcc` header relayed through the application's SMTP 
credentials.
   
   This strips CR and LF from the subject in:
   - `MimeMessageBuilder.setSubject` (`log4j-core` and `log4j-jakarta-smtp`)
   - the multipart send paths of both `SmtpManager` variants
   
   ## Testing
   `MimeMessageBuilderTest` (new): asserts a plain subject round-trips 
unchanged, and a subject containing CRLF has all CR/LF removed (making the 
remainder inert text within the single subject value). Both pass; no other 
behavior changes.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to