Known Vulnerabilities for Mailman by Gnu
Listed below are 10 of the newest known vulnerabilities associated with "Mailman" by "Gnu".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-44227 json | In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) t... | 8.8 - HIGH | 2021-12-02 | 2022-12-09 |
| CVE-2021-43332 json | In GNU Mailman before 2.1.36, the CSRF token for the Cgi/admindb.py admindb page contains an encrypted version of the list ad... | 6.5 - MEDIUM | 2021-11-12 | 2023-11-07 |
| CVE-2021-43331 json | In GNU Mailman before 2.1.36, a crafted URL to the Cgi/options.py user options page can execute arbitrary JavaScript for XSS. | 6.1 - MEDIUM | 2021-11-12 | 2023-11-07 |
| CVE-2021-42097 json | GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account.... | 8 - HIGH | 2021-10-21 | 2023-11-07 |
| CVE-2021-42096 json | GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A certain csrf_token value is derived from the admin passwor... | 4.3 - MEDIUM | 2021-10-21 | 2023-11-07 |
| CVE-2021-34337 json | An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to det... | 6.3 - MEDIUM | 2023-04-15 | 2023-04-25 |
| CVE-2020-15011 json | GNU Mailman before 2.1.33 allows arbitrary content injection via the Cgi/private.py private archive login page. | 4.3 - MEDIUM | 2020-06-24 | 2021-11-30 |
| CVE-2020-12137 json | GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may con... | 6.1 - MEDIUM | 2020-04-24 | 2023-11-07 |
| CVE-2020-12108 json | /options/mailman in GNU Mailman before 2.1.31 allows Arbitrary Content Injection. | 6.5 - MEDIUM | 2020-05-06 | 2023-11-07 |
| CVE-2018-13796 json | An issue was discovered in GNU Mailman before 2.1.28. A crafted URL can cause arbitrary text to be displayed on a web page fr... | 6.5 - MEDIUM | 2018-07-12 | 2023-11-07 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Gnu | Mailman | 2.1b1 | |||
| Application | Gnu | Mailman | 2.1.9 | |||
| Application | Gnu | Mailman | 2.1.8 | |||
| Application | Gnu | Mailman | 2.1.7 | |||
| Application | Gnu | Mailman | 2.1.6 | |||
| Application | Gnu | Mailman | 2.1.5.8 | |||
| Application | Gnu | Mailman | 2.1.5 | |||
| Application | Gnu | Mailman | 2.1.4 | |||
| Application | Gnu | Mailman | 2.1.33 | |||
| Application | Gnu | Mailman | 2.1.31 | |||
| Application | Gnu | Mailman | 2.1.30 | |||
| Application | Gnu | Mailman | 2.1.3 | |||
| Application | Gnu | Mailman | 2.1.29 | |||
| Application | Gnu | Mailman | 2.1.28 | |||
| Application | Gnu | Mailman | 2.1.27 | |||
| Application | Gnu | Mailman | 2.1.26 | |||
| Application | Gnu | Mailman | 2.1.25 | |||
| Application | Gnu | Mailman | 2.1.24 | |||
| Application | Gnu | Mailman | 2.1.23 | |||
| Application | Gnu | Mailman | 2.1.22 |