Описание
Cross-site request forgery (CSRF) vulnerability in the admin web interface in GNU Mailman before 2.1.15 allows remote attackers to hijack the authentication of administrators.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was not-affected [1:2.1.16-2ubuntu0.1]] |
| esm-infra/xenial | not-affected | |
| precise | released | 1:2.1.14-3ubuntu0.4 |
| trusty | not-affected | 1:2.1.16-2ubuntu0.1 |
| trusty/esm | DNE | trusty was not-affected [1:2.1.16-2ubuntu0.1] |
| upstream | released | 2.1.15-1 |
| vivid/stable-phone-overlay | DNE | |
| vivid/ubuntu-core | DNE | |
| xenial | not-affected |
Показывать по
EPSS
6.8 Medium
CVSS2
8.8 High
CVSS3
Связанные уязвимости
Cross-site request forgery (CSRF) vulnerability in the admin web interface in GNU Mailman before 2.1.15 allows remote attackers to hijack the authentication of administrators.
Cross-site request forgery (CSRF) vulnerability in the admin web interface in GNU Mailman before 2.1.15 allows remote attackers to hijack the authentication of administrators.
Cross-site request forgery (CSRF) vulnerability in the admin web inter ...
Cross-site request forgery (CSRF) vulnerability in the admin web interface in GNU Mailman before 2.1.15 allows remote attackers to hijack the authentication of administrators.
Уязвимость системы управления почтовыми рассылками GNU Mailman, позволяющая нарушителю подменить пользователя в ходе сессии администратора
EPSS
6.8 Medium
CVSS2
8.8 High
CVSS3