Описание
In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin password or make other changes.
Релиз | Статус | Примечание |
---|---|---|
bionic | released | 1:2.1.26-1ubuntu0.6 |
esm-apps/focal | needed | |
esm-infra/bionic | not-affected | 1:2.1.26-1ubuntu0.6 |
esm-infra/xenial | needed | |
focal | ignored | end of standard support, was needed |
trusty | ignored | end of standard support |
upstream | needs-triage | |
xenial | ignored | end of standard support |
Показывать по
10
6.8 Medium
CVSS2
8.8 High
CVSS3
Связанные уязвимости
CVSS3: 8
redhat
больше 3 лет назад
In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin password or make other changes.
CVSS3: 8.8
nvd
больше 3 лет назад
In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin password or make other changes.
CVSS3: 8.8
debian
больше 3 лет назад
In GNU Mailman before 2.1.38, a list member or moderator can get a CSR ...
6.8 Medium
CVSS2
8.8 High
CVSS3