Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2021:4916

Опубликовано: 02 дек. 2021
Источник: rocky
Оценка: Important

Описание

Important: mailman:2.1 security update

Mailman is a program used to help manage e-mail discussion lists.

Security Fix(es):

  • mailman: CSRF token bypass allows to perform CSRF attacks and admin takeover (CVE-2021-44227)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
mailmanx86_6412.module+el8.5.0+717+27fd1ba7.2mailman-2.1.29-12.module+el8.5.0+717+27fd1ba7.2.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 3 лет назад

In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin password or make other changes.

CVSS3: 8
redhat
больше 3 лет назад

In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin password or make other changes.

CVSS3: 8.8
nvd
больше 3 лет назад

In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin password or make other changes.

CVSS3: 8.8
debian
больше 3 лет назад

In GNU Mailman before 2.1.38, a list member or moderator can get a CSR ...

CVSS3: 8.8
github
больше 3 лет назад

Cross Site Request Forgery in mailman