Описание
GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks against list-archive visitors, because an HTTP reply from an archive web server may lack a MIME type, and a web browser may perform MIME sniffing, conclude that the MIME type should have been text/html, and execute JavaScript code.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | released | 1:2.1.26-1ubuntu0.1 |
| devel | DNE | |
| eoan | ignored | end of life |
| esm-apps/focal | released | 1:2.1.29-1ubuntu3.1 |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/bionic | released | 1:2.1.26-1ubuntu0.1 |
| esm-infra/xenial | released | 1:2.1.20-1ubuntu0.4 |
| focal | released | 1:2.1.29-1ubuntu3.1 |
| groovy | DNE | |
| hirsute | DNE |
Показывать по
Ссылки на источники
4.3 Medium
CVSS2
6.1 Medium
CVSS3
Связанные уязвимости
GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks against list-archive visitors, because an HTTP reply from an archive web server may lack a MIME type, and a web browser may perform MIME sniffing, conclude that the MIME type should have been text/html, and execute JavaScript code.
GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks against list-archive visitors, because an HTTP reply from an archive web server may lack a MIME type, and a web browser may perform MIME sniffing, conclude that the MIME type should have been text/html, and execute JavaScript code.
GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed app ...
GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks against list-archive visitors, because an HTTP reply from an archive web server may lack a MIME type, and a web browser may perform MIME sniffing, conclude that the MIME type should have been text/html, and execute JavaScript code.
4.3 Medium
CVSS2
6.1 Medium
CVSS3