Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2021-4826

Опубликовано: 24 нояб. 2021
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2021-4826: mailman:2.1 security update (IMPORTANT)

[3:2.1.29-12.1]

  • Fix for CVE-2021-42096
  • Fix for CVE-2021-42097
  • Resolves: #2021139, #2020692

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

Module mailman:2.1 is enabled

mailman

2.1.29-12.module+el8.5.0+20429+dde04a6e.1

Oracle Linux x86_64

Module mailman:2.1 is enabled

mailman

2.1.29-12.module+el8.5.0+20429+dde04a6e.1

Связанные CVE

Связанные уязвимости

suse-cvrf
больше 3 лет назад

Security update for mailman

rocky
больше 3 лет назад

Important: mailman:2.1 security update

CVSS3: 8
ubuntu
больше 3 лет назад

GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain a value within the context of an unprivileged user account, and then use that value in a CSRF attack against an admin (e.g., for account takeover).

CVSS3: 8
redhat
больше 3 лет назад

GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain a value within the context of an unprivileged user account, and then use that value in a CSRF attack against an admin (e.g., for account takeover).

CVSS3: 8
nvd
больше 3 лет назад

GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain a value within the context of an unprivileged user account, and then use that value in a CSRF attack against an admin (e.g., for account takeover).