Lucene search

K
cvelistMitreCVELIST:CVE-2021-43332
HistoryNov 12, 2021 - 8:45 p.m.

CVE-2021-43332

2021-11-1220:45:35
mitre
www.cve.org
6
mailman
csrf
vulnerability
password
brute-force

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

43.9%

In GNU Mailman before 2.1.36, the CSRF token for the Cgi/admindb.py admindb page contains an encrypted version of the list admin password. This could potentially be cracked by a moderator via an offline brute-force attack.

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

43.9%