GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A certain csrf_token value is derived from the admin password, and may be useful in conducting a brute-force attack against that password.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | alma-upgrade-mailman | May 4, 2022 | Oct 21, 2021 | |
| Centos_linux | — | centos-upgrade-mailmancentos-upgrade-mailman-debuginfocentos-upgrade-mailman-debugsource | Nov 26, 2021 | Oct 21, 2021 |
| Debian | debian-upgrade-mailman | Nov 29, 2021 | Oct 21, 2021 | |
| Freebsd | freebsd-upgrade-package-mailmanfreebsd-upgrade-package-mailman-with-htdig | Nov 4, 2022 | Oct 20, 2021 | |
| Huawei Euleros 2_0_sp3 | huawei-euleros-2_0_sp3-upgrade-mailman | Feb 24, 2022 | Oct 21, 2021 | |
| Huawei Euleros 2_0_sp5 | huawei-euleros-2_0_sp5-upgrade-mailman | Mar 2, 2022 | Oct 21, 2021 | |
| Oracle Solaris | oracle-solaris-11-4-upgrade-mail-mailman-2-1-33-11-4-40-0-1-107-1 | Dec 13, 2021 | Oct 21, 2021 | |
| Oracle_linux | — | oracle-linux-upgrade-mailman | Nov 25, 2021 | Oct 21, 2021 |
| Redhat_linux | redhat-upgrade-mailmanredhat-upgrade-mailman-debuginforedhat-upgrade-mailman-debugsource | Nov 26, 2021 | Oct 21, 2021 | |
| Rocky_linux | rocky-upgrade-mailmanrocky-upgrade-mailman-debuginforocky-upgrade-mailman-debugsource | Mar 12, 2024 | Oct 21, 2021 | |
| Suse | — | suse-upgrade-mailman | Nov 3, 2021 | Oct 21, 2021 |
| Ubuntu | ubuntu-pro-upgrade-mailmanubuntu-upgrade-mailman | Oct 22, 2021 | Oct 21, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub