Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4qpj-gxxg-jqg4

Опубликовано: 29 мая 2024
Источник: github
Github: Прошло ревью

Описание

Swiftmailer Sendmail transport arbitrary shell execution

Prior to 5.2.1, the sendmail transport (Swift_Transport_SendmailTransport) was vulnerable to an arbitrary shell execution if the "From" header came from a non-trusted source and no "Return-Path" is configured. This has been fixed in 5.2.1. If you are using sendmail as a transport, you are encouraged to upgrade as soon as possible.

Пакеты

Наименование

swiftmailer/swiftmailer

composer
Затронутые версииВерсия исправления

>= 4.0.0, < 5.2.1

5.2.1