CVE-2021-44227: CSRF
Published Dec 2, 2021
·Updated
In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin password or make other changes.
Affected Software
2 affected components
GNU Mailman<2.1.38
Debian Debian Linux=9.0
Remediation
Patch Available
Event History
Dec 2, 2021
CVE Published
via MITRE·02:52 AM
Data Sourced
via MITRE·02:52 AM
Description
Data Sourced
via NVD·03:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-44227.
2
What is the severity of CVE-2021-44227?
The severity of CVE-2021-44227 is high with a CVSS score of 8.8.
3
What is affected by CVE-2021-44227?
GNU Mailman versions before 2.1.38 and Debian Debian Linux version 9.0 are affected by CVE-2021-44227.
4
What is the impact of CVE-2021-44227?
A list member or moderator can exploit the vulnerability to craft an admin request and perform unauthorized actions such as setting a new admin password or making other changes.
5
How can CVE-2021-44227 be mitigated?
Upgrade to GNU Mailman version 2.1.38 or later to mitigate the vulnerability.