Описание
In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin password or make other changes.
A Cross-Site Request Forgery (CSRF) attack can be performed in mailman due to a CSRF token bypass. CSRF tokens are not checked against the right type of user when performing admin operations and a token created by a regular user can be used by an admin to perform an admin-level request, effectively bypassing the protection provided by CSRF tokens. A remote attacker with an account on the mailman system can use this flaw to perform a CSRF attack and perform operations on behalf of the victim admin.
Меры по смягчению последствий
Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 6 | mailman | Out of support scope | ||
Red Hat Enterprise Linux 7 | mailman | Fixed | RHSA-2021:4913 | 02.12.2021 |
Red Hat Enterprise Linux 8 | mailman | Fixed | RHSA-2021:4916 | 02.12.2021 |
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | mailman | Fixed | RHSA-2021:5081 | 13.12.2021 |
Red Hat Enterprise Linux 8.2 Extended Update Support | mailman | Fixed | RHSA-2021:5080 | 13.12.2021 |
Red Hat Enterprise Linux 8.4 Extended Update Support | mailman | Fixed | RHSA-2021:4915 | 02.12.2021 |
Показывать по
Дополнительная информация
Статус:
EPSS
8 High
CVSS3
Связанные уязвимости
In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin password or make other changes.
In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin password or make other changes.
In GNU Mailman before 2.1.38, a list member or moderator can get a CSR ...
EPSS
8 High
CVSS3