CVE-2010-3089
Summary
| CVE | CVE-2010-3089 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-09-15 20:00:02 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities in GNU Mailman before 2.1.14rc1 allow remote authenticated users to inject arbitrary web script or HTML via vectors involving (1) the list information field or (2) the list description field. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
SingleConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:S/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Gnu | Mailman | 2.1 | All | All | All |
| Application | Gnu | Mailman | 2.1 | alpha | All | All |
| Application | Gnu | Mailman | 2.1 | beta | All | All |
| Application | Gnu | Mailman | 2.1 | stable | All | All |
| Application | Gnu | Mailman | 2.1.1 | All | All | All |
| Application | Gnu | Mailman | 2.1.10 | All | All | All |
| Application | Gnu | Mailman | 2.1.11 | All | All | All |
| Application | Gnu | Mailman | 2.1.11 | rc1 | All | All |
| Application | Gnu | Mailman | 2.1.11 | rc2 | All | All |
| Application | Gnu | Mailman | 2.1.12 | All | All | All |
| Application | Gnu | Mailman | 2.1.13 | rc1 | All | All |
| Application | Gnu | Mailman | 2.1.2 | All | All | All |
| Application | Gnu | Mailman | 2.1.3 | All | All | All |
| Application | Gnu | Mailman | 2.1.4 | All | All | All |
| Application | Gnu | Mailman | 2.1.5 | All | All | All |
| Application | Gnu | Mailman | 2.1.6 | All | All | All |
| Application | Gnu | Mailman | 2.1.7 | All | All | All |
| Application | Gnu | Mailman | 2.1.8 | All | All | All |
| Application | Gnu | Mailman | 2.1.9 | All | All | All |
| Application | Gnu | Mailman | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [Mailman-Announce] Mailman security patch. | af854a3a-2127-422b-91ae-364da2661108 | mail.python.org | |
| Debian update for mailman - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Fedora update for mailman - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Bug 631881 – CVE-2010-3089 mailman: Multiple security flaws leading to cross-site scripting (XSS) attacks | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| USN-1069-1: Mailman vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| APPLE-SA-2011-03-21-1 Mac OS X v10.6.7 and Security Update 2011-001 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| [SECURITY] Fedora 13 Update: mailman-2.1.12-16.fc13 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2011:009 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Red Hat update for mailman - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| [Mailman-Announce] Mailman security patch. | af854a3a-2127-422b-91ae-364da2661108 | mail.python.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| 'Re: [oss-security] CVE Request: mailman' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| openSUSE-SU-2011:0424-1 (low): mailman security update to fix XSS vulner | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Debian -- Security Information -- DSA-2170-1 mailman | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Ubuntu update for mailman - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| [SECURITY] Fedora 14 Update: mailman-2.1.13-6.fc14.1 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Bug 631859 – Mailman: Cross-site scripting (XSS) in list information overview | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| About the security content of Mac OS X v10.6.7 and Security Update 2011-001 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| 'Re: [oss-security] CVE Request: mailman' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| 'Re: [oss-security] CVE Request: mailman' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Mailman List Description Two Script Insertion Vulnerabilities - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| 'Re: [oss-security] CVE Request: mailman' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| 2.1.14rc1 : GNU Mailman | af854a3a-2127-422b-91ae-364da2661108 | launchpad.net | |
| Red Hat update for mailman - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| '[oss-security] CVE Request: mailman' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Red Hat Customer Portal | MITRE | access.redhat.com | |
| Red Hat Customer Portal | MITRE | access.redhat.com | |
| access.redhat.com | CVE-2010-3089 | MITRE | access.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.