GNU Mailman before 2.1.33 allows arbitrary content injection via the Cgi/private.py private archive login page.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade mailman | May 4, 2022 | Jun 24, 2020 |
| Centos_linux | — | Upgrade mailman-debugsourceUpgrade mailman-debuginfoUpgrade mailman | Jun 1, 2021 | Jun 24, 2020 |
| Debian | — | Upgrade mailman | Jul 2, 2020 | Jun 24, 2020 |
| Huawei Euleros 2_0_sp2 | — | Upgrade mailman | Feb 22, 2021 | Jun 24, 2020 |
| Huawei Euleros 2_0_sp3 | — | Upgrade mailman | Jan 20, 2021 | Jun 24, 2020 |
| Huawei Euleros 2_0_sp5 | — | Upgrade mailman | Nov 2, 2020 | Jun 24, 2020 |
| Oracle_linux | — | Upgrade mailman | May 26, 2021 | May 7, 2020 |
| Redhat_linux | — | No solution existsUpgrade mailman-debugsourceUpgrade mailman-debuginfoUpgrade mailman | May 21, 2021 | Jun 24, 2020 |
| Rocky_linux | — | Upgrade mailman-debugsourceUpgrade mailman-debuginfoUpgrade mailman | Mar 12, 2024 | Jun 24, 2020 |
| Suse | — | Upgrade mailman | Jul 16, 2020 | Jun 24, 2020 |
| Ubuntu | — | Upgrade mailman | Jun 30, 2020 | Jun 24, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub