CVE-2020-12108: Medium severity cpanel gnu mailman vulnerability
Published May 6, 2020
·Updated
/options/mailman in GNU Mailman before 2.1.31 allows Arbitrary Content Injection.
Affected Software
11 affected components
debian/mailman
GNU Mailman<2.1.31
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Fedoraproject Fedora=31
openSUSE Backports SLE=15.0-sp1
openSUSE Backports SLE=15.0-sp2
openSUSE Leap=15.1
openSUSE Leap=15.2
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Remediation
Patch Available
Event History
May 6, 2020
CVE Published
via MITRE·02:50 PM
Data Sourced
via MITRE·02:50 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·11:37 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·02:21 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2020-12108?
CVE-2020-12108 is a vulnerability in GNU Mailman before 2.1.31 that allows Arbitrary Content Injection.
2
What is the severity of CVE-2020-12108?
The severity of CVE-2020-12108 is medium with a CVSS score of 6.5.
3
How does CVE-2020-12108 affect GNU Mailman?
CVE-2020-12108 affects GNU Mailman before version 2.1.31, allowing Arbitrary Content Injection.
4
How can I fix CVE-2020-12108?
To fix CVE-2020-12108, update GNU Mailman to version 2.1.31 or later.
5
Where can I find more information about CVE-2020-12108?
More information about CVE-2020-12108 can be found at the following references: [Reference 1](https://bugs.launchpad.net/mailman/+bug/1873722), [Reference 2](https://code.launchpad.net/mailman), [Reference 3](https://mail.python.org/pipermail/mailman-announce/).