Vulnerability CVE-2021-42097: Information

Description

GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain a value within the context of an unprivileged user account, and then use that value in a CSRF attack against an admin (e.g., for account takeover).

Severity: HIGH (8.0) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Published: Oct. 21, 2021
Modified: Nov. 7, 2023
Error type identifier: CWE-352

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
mailmansisyphus2.1.35-alt12.1.39-alt1ALT-PU-2021-3235-1289090Fixed
mailmansisyphus_e2k2.1.39-alt12.1.39-alt1ALT-PU-2022-3551-1-Fixed
mailmanp102.1.37-alt12.1.38-alt1ALT-PU-2021-3277-1289142Fixed
mailmanp92.1.37-alt12.1.37-alt1ALT-PU-2021-3299-1289143Fixed
mailmanc10f12.1.37-alt12.1.38-alt1ALT-PU-2021-3277-1289142Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:gnu:mailman:*:*:*:*:*:*:*:*
      End excliding
      2.1.35

      Configuration 2

      cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*