Your submission was sent successfully! Close

CVE-2021-44227

Published: 2 December 2021

In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin password or make other changes.

Priority

Medium

CVSS 3 base score: 8.8

Status

Package Release Status
mailman
Launchpad, Ubuntu, Debian
bionic
Released (1:2.1.26-1ubuntu0.6)
focal Needed

trusty Ignored
(out of standard support)
upstream Needs triage

xenial Needed