VDB
Sign up
HIGH8.8

GHSA-2pm6-9fhx-vvg3

The mailqueue TYPO3 extension has Insecure Deserialization in `TransportFailure` class

Quick fix

GHSA-2pm6-9fhx-vvg3 — cpsit/typo3-mailqueue: upgrade to the fixed version with the command below.

composer require cpsit/typo3-mailqueue:^0.4.5

Details

## Description

The extension fails to properly define allowed classes used when deserializing transport failure metadata. An attacker may exploit this to execute untrusted serialized code. Note that an active exploit requires write access to the directory configured at `$GLOBALS['TYPO3_CONF_VARS']['MAIL']['transport_spool_filepath']`.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/cpsit/typo3-mailqueue
Introduced in: 0Fixed in: 0.4.5
Fixcomposer require cpsit/typo3-mailqueue:^0.4.5
Packagist/cpsit/typo3-mailqueue
Introduced in: 0.5.0Fixed in: 0.5.2
Fixcomposer require cpsit/typo3-mailqueue:^0.5.2

References