Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v83x-78q3-gr2j

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 5.3
CVSS3: 5.4

Описание

GNU Mailman Postorius Access Control Issues

An issue was discovered in views/list.py in GNU Mailman Postorius before 1.3.5. An attacker (logged into any account) can send a crafted POST request to unsubscribe any user from a mailing list, also revealing whether that address was subscribed in the first place.

Пакеты

Наименование

postorius

pip
Затронутые версииВерсия исправления

< 1.3.5

1.3.5

EPSS

Процентиль: 44%
0.00213
Низкий

5.3 Medium

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 5.4
ubuntu
больше 4 лет назад

An issue was discovered in views/list.py in GNU Mailman Postorius before 1.3.5. An attacker (logged into any account) can send a crafted POST request to unsubscribe any user from a mailing list, also revealing whether that address was subscribed in the first place.

CVSS3: 5.4
nvd
больше 4 лет назад

An issue was discovered in views/list.py in GNU Mailman Postorius before 1.3.5. An attacker (logged into any account) can send a crafted POST request to unsubscribe any user from a mailing list, also revealing whether that address was subscribed in the first place.

CVSS3: 5.4
debian
больше 4 лет назад

An issue was discovered in views/list.py in GNU Mailman Postorius befo ...

EPSS

Процентиль: 44%
0.00213
Низкий

5.3 Medium

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-284