Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-43921

Опубликовано: 20 апр. 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 5.3

Описание

GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to create lists via the /mailman/create endpoint. NOTE: multiple third parties report that they are unable to reproduce this, regardless of whether cPanel or WHM is used.

РелизСтатусПримечание
devel

DNE

esm-apps/focal

not-affected

code not present
esm-infra-legacy/xenial

not-affected

code not present
esm-infra/bionic

not-affected

code not present
esm-infra/xenial

not-affected

code not present
focal

ignored

end of standard support, was needs-triage
jammy

DNE

noble

DNE

oracular

DNE

plucky

DNE

Показывать по

EPSS

Процентиль: 36%
0.00432
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
больше 1 года назад

GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to create lists via the /mailman/create endpoint. NOTE: multiple third parties report that they are unable to reproduce this, regardless of whether cPanel or WHM is used.

CVSS3: 5.3
debian
больше 1 года назад

GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthentic ...

CVSS3: 5.3
github
больше 1 года назад

GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to create lists via the /mailman/create endpoint.

CVSS3: 5.8
fstec
больше 1 года назад

Уязвимость пакета управления рассылками электронных писем GNU Mailman, связанная с недостатками механизма авторизации, позволяющая нарушителю создавать произвольные файлы

EPSS

Процентиль: 36%
0.00432
Низкий

5.3 Medium

CVSS3