shaggyinsomniac opened a new pull request, #4258: URL: https://github.com/apache/logging-log4j2/pull/4258
## Description The `SmtpAppender` subject is produced by a PatternLayout serializer and commonly embeds event data (message, MDC, throwable). CR/LF sequences in that data currently flow into `MimeMessage.setSubject` unsanitized, allowing mail header injection when an attacker can influence logged content — for example a logged username or error message containing `\r\nBcc: [email protected]` results in an injected `Bcc` header relayed through the application's SMTP credentials. This strips CR and LF from the subject in: - `MimeMessageBuilder.setSubject` (`log4j-core` and `log4j-jakarta-smtp`) - the multipart send paths of both `SmtpManager` variants ## Testing `MimeMessageBuilderTest` (new): asserts a plain subject round-trips unchanged, and a subject containing CRLF has all CR/LF removed (making the remainder inert text within the single subject value). Both pass; no other behavior changes. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
