{"id":"GHSA-4qpj-gxxg-jqg4","summary":"Swiftmailer Sendmail transport arbitrary shell execution","details":"Prior to 5.2.1, the sendmail transport (`Swift_Transport_SendmailTransport`) was vulnerable to an arbitrary shell execution if the \"From\" header came from a non-trusted source and no \"Return-Path\" is configured. This has been fixed in 5.2.1. If you are using sendmail as a transport, you are encouraged to upgrade as soon as possible.","modified":"2024-12-04T05:34:02.303434Z","published":"2024-05-29T13:13:16Z","database_specific":{"nvd_published_at":null,"cwe_ids":[],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2024-05-29T13:13:16Z"},"references":[{"type":"WEB","url":"https://github.com/swiftmailer/swiftmailer/commit/b4b78af55e5e87f5ff07c06c6be7963c44562f80"},{"type":"WEB","url":"https://github.com/swiftmailer/swiftmailer/commit/efc430606a5faed864b969adfbdc5363ce2115a2"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/swiftmailer/swiftmailer/2014-06-13.yaml"},{"type":"PACKAGE","url":"https://github.com/swiftmailer/swiftmailer"},{"type":"WEB","url":"https://web.archive.org/web/20150219063146/http://blog.swiftmailer.org/post/88660759928/security-fix-swiftmailer-5-2-1-released"},{"type":"WEB","url":"http://blog.swiftmailer.org/post/88660759928/security-fix-swiftmailer-5-2-1-released"}],"affected":[{"package":{"name":"swiftmailer/swiftmailer","ecosystem":"Packagist","purl":"pkg:composer/swiftmailer/swiftmailer"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.0.0"},{"fixed":"5.2.1"}]}],"versions":["4.1.3","4.1.4","4.1.5","4.1.6","4.1.7","v4.1.8","v4.2.0","v4.2.1","v4.2.2","v4.3.0","v4.3.1","v5.0.0","v5.0.1","v5.0.2","v5.0.3","v5.1.0","v5.2.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-4qpj-gxxg-jqg4/GHSA-4qpj-gxxg-jqg4.json"}}],"schema_version":"1.9.0"}