CVE-2021-42096: CSRF
GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A certain csrftoken value is derived from the admin password, and may be useful in conducting a brute-force attack against that password.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-42096?
CVE-2021-42096 is a vulnerability in GNU Mailman before version 2.1.35 that may allow remote Privilege Escalation through a brute-force attack against the admin password.
What is the severity of CVE-2021-42096?
The severity of CVE-2021-42096 is medium with a CVSS severity score of 4.3.
Which software versions are affected by CVE-2021-42096?
CVE-2021-42096 affects GNU Mailman versions before 2.1.35.
How can I fix CVE-2021-42096?
To fix CVE-2021-42096, you should update GNU Mailman to version 2.1.35 or newer.
Where can I find more information about CVE-2021-42096?
You can find more information about CVE-2021-42096 on the MITRE website (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-42096), the Python Mailman mailing list (https://mail.python.org/archives/list/mailman-announce@python.org/thread/IKCO6JU755AP5G5TKMBJL6IEZQTTNPDQ/), and the OSS Security mailing list (https://www.openwall.com/lists/oss-security/2021/10/21/4).