{"id":"GHSA-xjw3-5r5c-m5ph","summary":"typo3 Security fix for Flow Swift Mailer package","details":"A remote code execution vulnerability has been found in the Swift Mailer library (swiftmailer/swiftmailer) recently. See this advisory for details. If you are not using the default mail() transport, this particular problem  does not affect you. Upgrading is of course still recommended!","modified":"2024-12-02T05:46:56.409211Z","published":"2024-06-05T20:47:53Z","database_specific":{"nvd_published_at":null,"cwe_ids":[],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-06-05T20:47:53Z"},"references":[{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/swiftmailer/2017-01-06.yaml"},{"type":"PACKAGE","url":"https://github.com/neos/swiftmailer"},{"type":"WEB","url":"https://www.neos.io/blog/flow-sa-2017-01.html"}],"affected":[{"package":{"name":"typo3/swiftmailer","ecosystem":"Packagist","purl":"pkg:composer/typo3/swiftmailer"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.1.0"},{"fixed":"4.1.99"}]}],"versions":["4.1.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/06/GHSA-xjw3-5r5c-m5ph/GHSA-xjw3-5r5c-m5ph.json"}},{"package":{"name":"typo3/swiftmailer","ecosystem":"Packagist","purl":"pkg:composer/typo3/swiftmailer"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.4.0"},{"fixed":"5.4.5"}]}],"versions":["5.4.1","5.4.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/06/GHSA-xjw3-5r5c-m5ph/GHSA-xjw3-5r5c-m5ph.json"}}],"schema_version":"1.9.0"}