Where
-Infinity
0

Vendor Risk Score

See how mailman compares to other vendors in security performance

View Risk Score →

On 5/8/26 06:19, Demi Marie Obenour wrote: I know that the (unrelated) h2o project (a C HTTP server library and daemon) does tell users to use its master branch. I would like to note that telling users to use the default branch after every release.

With my upstream-elsewhere hat on, keeping the default branch in releasable shape and doing a new release soon after security fixes should be feasible. If it's not feasible, that probably indicates other problems. (I mean that in general and not with regard to Postorius or h2o, specially. I have not looked at these or their processes in detail.)

Best, Sebastian

The current released version of Postorius, and earlier versions, contain an XSS vulnerability in the admin UI. A fix was merged upstream in January 2025, which included documentation of the security issue in the news file[1], but no release has been made since, and I don't see any previous discussion in the oss-security archives. Distributions packaging the latest release that have not backported this fix are vulnerable. I have heard that this issue is being actively exploited.

[1]: https://gitlab.com/mailman/postorius/-/commit/c4706abd05ba6bcf472fc674b160d3a9d6a4868b

Severity
4.3
XSS
AV:N/AC:M/Au:N/C:N/I:P/A:N

Common Vulnerabilities and Exposures assigned an identifier CVE-2008-0564 to the following vulnerability:

Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2.1.10b1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) editing templates and (2) the list's "info attribute" in the web administrator interface, a different vulnerability than CVE-2006-3636.

References: http://mail.python.org/pipermail/mailman-announce/2008-February/000096.html

1 / 2
Source: Red Hat
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203