{"id":"GHSA-f57v-q966-7fh6","aliases":[],"url":"https://o3.security/vulnerability/GHSA-f57v-q966-7fh6","summary":"Monolog Header injection in NativeMailerHandler","details":"A header injection vulnerability has been identified in the NativeMailerHandler of the Monolog library. This vulnerability may allow an attacker to manipulate email headers when log messages are sent via email.","published":"2024-05-15T23:08:13Z","modified":"2024-11-29T05:40:52.145864Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"monolog/monolog","fixedVersion":"1.12.0"}],"fix":{"url":"https://github.com/Seldaek/monolog/pull/448#issuecomment-68208704","label":"Seldaek/monolog#448"},"references":[{"type":"WEB","url":"https://github.com/Seldaek/monolog/issues/458"},{"type":"WEB","url":"https://github.com/Seldaek/monolog/pull/448#issuecomment-68208704"},{"type":"WEB","url":"https://github.com/Seldaek/monolog/commit/515a096c864b00b3967f7f601680f85d4a2e4001"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/monolog/monolog/2014-12-29-1.yaml"},{"type":"PACKAGE","url":"https://github.com/Seldaek/monolog"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-11-29T05:40:52.145864Z"}}