0
0
mirror of https://github.com/PHPMailer/PHPMailer.git synced 2024-09-20 01:52:15 +02:00

Changelog

This commit is contained in:
Marcus Bointon 2021-06-15 19:53:27 +02:00
parent 45f3c18dc6
commit c2f191be6b
No known key found for this signature in database
GPG Key ID: DE31CD6EB646AA24

View File

@ -1,5 +1,7 @@
# PHPMailer Change Log
* **SECURITY** Fixes CVE-2021-3603 that may permit untrusted code to be run from an address validator, see SECURITY.md for details
## Version 6.4.1 (April 29th, 2021)
* **SECURITY** Fixes CVE-2020-36326, a regression of CVE-2018-19296 object injection introduced in 6.1.8, see SECURITY.md for details
* Reject more file paths that look like URLs, matching RFC3986 spec, blocking URLS using schemes such as `ssh2`