GHSA-45xg-4w5x-j429

Suggest an improvement
Source
https://github.com/advisories/GHSA-45xg-4w5x-j429
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-45xg-4w5x-j429/GHSA-45xg-4w5x-j429.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-45xg-4w5x-j429
Published
2024-05-30T18:59:33Z
Modified
2024-12-06T05:34:48.176495Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
TYPO3 Arbitrary Shell Execution in Swiftmailer library
Details

The swiftmailer library in use allows to execute arbitrary shell commands if the "From" header comes from a non-trusted source and no "Return-Path" is configured. Affected are only TYPO3 installation the configuration option

$GLOBALS['TYPO3_CONF_VARS']['MAIL']['transport'] 

is set to "sendmail". Installations with the default configuration are not affected.

Database specific
{
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-20"
    ],
    "severity": "HIGH",
    "nvd_published_at": null,
    "github_reviewed_at": "2024-05-30T18:59:33Z"
}
References

Affected packages

Packagist / typo3/cms

Package

Name
typo3/cms
Purl
pkg:composer/typo3/cms

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.2.6

Affected versions

6.*

6.2.0
6.2.1
6.2.2
6.2.3
6.2.4
6.2.5

Packagist / typo3/cms

Package

Name
typo3/cms
Purl
pkg:composer/typo3/cms

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.1.0
Fixed
6.1.12

Packagist / typo3/cms

Package

Name
typo3/cms
Purl
pkg:composer/typo3/cms

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.7.0
Fixed
4.7.20

Packagist / typo3/cms

Package

Name
typo3/cms
Purl
pkg:composer/typo3/cms

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.5.0
Fixed
4.5.37