GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain a value within the context of an unprivileged user account, and then use that value in a CSRF attack against an admin (e.g., for account takeover).
CVSS Details
- CVSS 3.1 Base Score: 8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade mailman | May 4, 2022 | Oct 21, 2021 |
| Amazon Linux Ami 2 | — | Upgrade mailmanUpgrade mailman-debuginfo | Jul 4, 2022 | Oct 21, 2021 |
| Centos_linux | — | Upgrade mailmanUpgrade mailman-debuginfoUpgrade mailman-debugsource | Nov 26, 2021 | Oct 21, 2021 |
| Debian | — | Upgrade mailman | Nov 29, 2021 | Oct 21, 2021 |
| Freebsd | — | Upgrade mailmanUpgrade mailman-with-htdig | Nov 4, 2022 | Oct 20, 2021 |
| Huawei Euleros 2_0_sp3 | — | Upgrade mailman | Feb 24, 2022 | Oct 21, 2021 |
| Huawei Euleros 2_0_sp5 | — | Upgrade mailman | Mar 2, 2022 | Oct 21, 2021 |
| Oracle Solaris | — | Upgrade mail/mailman to version 2.1.33-11.4.40.0.1.107.1 on Solaris 11.4 | Dec 13, 2021 | Oct 21, 2021 |
| Oracle_linux | — | Upgrade mailman | Nov 25, 2021 | Oct 21, 2021 |
| Redhat_linux | — | Upgrade mailmanUpgrade mailman-debugsourceUpgrade mailman-debuginfoNo solution exists | Nov 26, 2021 | Oct 21, 2021 |
| Rocky_linux | — | Upgrade mailman-debugsourceUpgrade mailmanUpgrade mailman-debuginfo | Mar 12, 2024 | Oct 21, 2021 |
| Suse | — | Upgrade mailman | Nov 3, 2021 | Oct 21, 2021 |
| Ubuntu | — | Upgrade mailmanUpgrade mailman (Ubuntu Pro) | Oct 22, 2021 | Oct 21, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub