CVE-2020-15011
Summary
| CVE | CVE-2020-15011 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-06-24 12:15:00 UTC |
| Updated | 2021-11-30 22:29:00 UTC |
| Description | GNU Mailman before 2.1.33 allows arbitrary content injection via the Cgi/private.py private archive login page. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [security-announce] openSUSE-SU-2020:1752-1: moderate: Recommended updat |
SUSE |
lists.opensuse.org |
|
| Debian -- Security Information -- DSA-4991-1 mailman |
DEBIAN |
www.debian.org |
|
| [SECURITY] [DLA 2276-1] mailman security update |
MLIST |
lists.debian.org |
|
| USN-4406-1: Mailman vulnerability | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| [SECURITY] [DLA 2265-1] mailman security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| Bug #1877379 “Arbitrary Content Injection via the private archiv...” : Bugs : GNU Mailman |
MISC |
bugs.launchpad.net |
Issue Tracking, Patch, Third Party Advisory |
| [security-announce] openSUSE-SU-2020:1707-1: moderate: Recommended updat |
SUSE |
lists.opensuse.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159210 Oracle Enterprise Linux Security Update for mailman:2.1 (ELSA-2021-1751)
- 178829 Debian Security Update for mailman (DSA 4991-1)
- 198576 Ubuntu Security Notification for Mailman Vulnerabilities (USN-5121-2)
- 239311 Red Hat Update for mailman:2.1 (RHSA-2021:1751)
- 377570 Alibaba Cloud Linux Security Update for mailman:2.1 (ALINUX3-SA-2022:0093)
- 940352 AlmaLinux Security Update for mailman:2.1 (ALSA-2021:1751)
- 960755 Rocky Linux Security Update for mailman:2.1 (RLSA-2021:1751)