GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A certain csrf_token value is derived from the admin password, and may be useful in conducting a brute-force attack against that password.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade mailman | May 4, 2022 | Oct 21, 2021 |
| Centos_linux | — | Upgrade mailmanUpgrade mailman-debugsourceUpgrade mailman-debuginfo | Nov 26, 2021 | Oct 21, 2021 |
| Debian | — | Upgrade mailman | Nov 29, 2021 | Oct 21, 2021 |
| Freebsd | — | Upgrade mailman-with-htdigUpgrade mailman | Nov 4, 2022 | Oct 20, 2021 |
| Huawei Euleros 2_0_sp3 | — | Upgrade mailman | Feb 24, 2022 | Oct 21, 2021 |
| Huawei Euleros 2_0_sp5 | — | Upgrade mailman | Mar 2, 2022 | Oct 21, 2021 |
| Oracle Solaris | — | Upgrade mail/mailman to version 2.1.33-11.4.40.0.1.107.1 on Solaris 11.4 | Dec 13, 2021 | Oct 21, 2021 |
| Oracle_linux | — | Upgrade mailman | Nov 25, 2021 | Oct 21, 2021 |
| Redhat_linux | — | Upgrade mailmanUpgrade mailman-debuginfoUpgrade mailman-debugsource | Nov 26, 2021 | Oct 21, 2021 |
| Rocky_linux | — | Upgrade mailmanUpgrade mailman-debuginfoUpgrade mailman-debugsource | Mar 12, 2024 | Oct 21, 2021 |
| Suse | — | Upgrade mailman | Nov 3, 2021 | Oct 21, 2021 |
| Ubuntu | — | Upgrade mailmanUpgrade mailman (Ubuntu Pro) | Oct 22, 2021 | Oct 21, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub