https://seclists.org/oss-sec/2025/q2/70: 3 new CVE's in old branch of GNU mailman
Published Apr 21, 2025
·Updated
Affected Software
1 affected component
GNU Mailman
Frequently Asked Questions
1
Does this affect a stock GNU Mailman 2.1.39 installation?
The reported issues could not be reproduced on a stock GNU Mailman 2.1.39 installation. The available discussion also says the code handling the private endpoint does not show an apparent path from the username POST parameter to path construction.
2
Is the exposure potentially limited to the cPanel and WHM bundled version?
The reports identify GNU Mailman 2.1.39 as bundled with cPanel and WHM. The discussion raises, but does not confirm, that vendor modifications in cPanel LLC's distributed version may be required for the reported behavior.