CVE-2021-44227
Summary
| CVE | CVE-2021-44227 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-12-02 03:15:00 UTC |
| Updated | 2022-12-09 16:07:00 UTC |
| Description | In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin password or make other changes. |
Risk And Classification
Problem Types: CWE-352
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] [DLA 3049-1] mailman security update | MLIST | lists.debian.org | |
| Bug #1952384 “A CSRF vulnerability could allow a list moderator ...” : Bugs : GNU Mailman | MISC | bugs.launchpad.net | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159545 Oracle Enterprise Linux Security Update for mailman (ELSA-2021-4913)
- 159546 Oracle Enterprise Linux Security Update for mailman:2.1 (ELSA-2021-4916)
- 179367 Debian Security Update for mailman (DLA 3049-1)
- 180113 Debian Security Update for mailman (CVE-2021-44227)
- 198600 Ubuntu Security Notification for Mailman Vulnerability (USN-5180-1)
- 239926 Red Hat Update for mailman:2.1 (RHSA-2021:4916)
- 239927 Red Hat Update for mailman:2.1 (RHSA-2021:4915)
- 239928 Red Hat Update for mailman (RHSA-2021:4913)
- 239960 Red Hat Update for mailman:2.1 (RHSA-2021:5080)
- 257134 CentOS Security Update for mailman (CESA-2021:4913)
- 353123 Amazon Linux Security Advisory for mailman : ALAS2-2022-1740
- 377175 Alibaba Cloud Linux Security Update for mailman (ALINUX2-SA-2021:0069)
- 671336 EulerOS Security Update for mailman (EulerOS-SA-2022-1277)
- 671709 EulerOS Security Update for mailman (EulerOS-SA-2022-1745)
- 690768 Free Berkeley Software Distribution (FreeBSD) Security Update for mailman less than 2.1.38 (0d6efbe3-52d9-11ec-9472-e3667ed6088e)
- 752189 SUSE Enterprise Linux Security Update for mailman (SUSE-SU-2022:1886-1)
- 940085 AlmaLinux Security Update for mailman:2.1 (ALSA-2021:4916)
- 960373 Rocky Linux Security Update for mailman:2.1 (RLSA-2021:4916)