CVE-2021-42097: CSRF
GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrftoken value is not specific to a single user account. An attacker can obtain a value within the context of an unprivileged user account, and then use that value in a CSRF attack against an admin (e.g., for account takeover).
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this security issue?
The vulnerability ID of this security issue is CVE-2021-42097.
What is the severity level of CVE-2021-42097?
CVE-2021-42097 has a severity level of high.
What is the affected software for CVE-2021-42097?
The affected software for CVE-2021-42097 is GNU Mailman versions before 2.1.35.
How can an attacker exploit CVE-2021-42097?
An attacker can exploit CVE-2021-42097 by obtaining a csrf_token value within the context of an unprivileged user account and using it in a CSRF attack against an admin.
Are there any known remedies for CVE-2021-42097?
Yes, there are known remedies for CVE-2021-42097. For Debian, it is recommended to upgrade to version 1:2.1.29-1+deb10u5 or 1:2.1.29-1+deb10u2. For Ubuntu, upgrading to version 2.1.35 or 1:2.1.29-1ubuntu3.1 is recommended.