Your submission was sent successfully! Close

CVE-2021-44227

Published: 02 December 2021

In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin password or make other changes.

Priority

Medium

CVSS 3 base score: 8.8

Status

Package Release Status
mailman
Launchpad, Ubuntu, Debian
Upstream Needs triage

Ubuntu 20.04 LTS (Focal Fossa) Needed

Ubuntu 18.04 LTS (Bionic Beaver)
Released (1:2.1.26-1ubuntu0.6)
Ubuntu 16.04 ESM (Xenial Xerus) Needed

Ubuntu 14.04 ESM (Trusty Tahr) Ignored
(out of standard support)
Patches:
Upstream: https://bazaar.launchpad.net/~mailman-coders/mailman/2.1/revision/1882