{"id":"GHSA-rq6q-hjvh-5mwh","aliases":[],"url":"https://o3.security/vulnerability/GHSA-rq6q-hjvh-5mwh","summary":"Flow Swift Mailer package Remote code execution","details":"A remote code execution vulnerability has been found in the Swift Mailer library (swiftmailer/swiftmailer) recently. [See this advisory for details](http://legalhackers.com/advisories/SwiftMailer-Exploit-Remote-Code-Exec-CVE-2016-10074-Vuln.html). If you are not using the default mail() transport, this particular problem  does not affect you. Upgrading is of course still recommended!","published":"2024-05-17T23:06:50Z","modified":"2024-12-02T05:28:57.574716Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"neos/swiftmailer","fixedVersion":"5.4.5"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/neos/swiftmailer/2017-01-06.yaml"},{"type":"PACKAGE","url":"https://github.com/neos/swiftmailer"},{"type":"WEB","url":"https://www.neos.io/blog/flow-sa-2017-01.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-02T05:28:57.574716Z"}}