Описание
In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin password or make other changes.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | released | 1:2.1.26-1ubuntu0.6 |
| esm-apps/focal | needed | |
| esm-infra/bionic | released | 1:2.1.26-1ubuntu0.6 |
| esm-infra/xenial | needed | |
| focal | ignored | end of standard support, was needed |
| trusty | ignored | end of standard support |
| upstream | needs-triage | |
| xenial | ignored | end of standard support |
Показывать по
10
6.8 Medium
CVSS2
8.8 High
CVSS3
Связанные уязвимости
CVSS3: 8
redhat
около 4 лет назад
In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin password or make other changes.
CVSS3: 8.8
nvd
около 4 лет назад
In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin password or make other changes.
CVSS3: 8.8
debian
около 4 лет назад
In GNU Mailman before 2.1.38, a list member or moderator can get a CSR ...
6.8 Medium
CVSS2
8.8 High
CVSS3