Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[GOVCMSD10-444] Mark drupal/swiftmailer module as 'obsolete' #995

Merged
merged 2 commits into from Jan 25, 2024

Conversation

Tara-Wij
Copy link
Contributor

Security Advisory - https://www.drupal.org/sa-contrib-2024-006
Project: Swift Mailer
Date: 2024-January-24
Security risk: Moderately critical 12∕25 AC:Basic/A:None/CI:Some/II:None/E:Theoretical/TD:Default
Vulnerability: Access Bypass
Affected versions:

Description:

The Drupal Swift Mailer module extends the basic e-mail sending functionality provided by Drupal by delegating all e-mail handling to the Swift Mailer library. This enables your site to take advantage of the many features which the Swift Mailer library provides.

The module could allow an attacker to gain widespread access to a Drupal site. This vulnerability is mitigated by the fact that an attacker must have a means to trigger sending an email with a body that they can control, which would requires either another contributed module or custom integration.

Solution:

Uninstall this module immediately. The swiftmailer library has been unsupported for a year, and this module is now also unsupported.

Step 1: Mark swiftmailer module as 'obsolete' in GovCMS distribution.

@ruwanl ruwanl merged commit dc42043 into govCMS:3.x-develop Jan 25, 2024
2 checks passed
@ruwanl ruwanl changed the title [GOVCMSD10-439] Mark drupal/swiftmailer module as 'obsolete' [GOVCMSD10-444] Mark drupal/swiftmailer module as 'obsolete' Jan 25, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants