Lucene search

K
osvGoogleOSV:GHSA-XQ58-69H2-765M
HistoryDec 16, 2021 - 3:27 p.m.

Cross Site Request Forgery in mailman

2021-12-1615:27:06
Google
osv.dev
14
gnu mailman
cross site request forgery
admin request
csrf token
list member
moderator
admin password
security vulnerability

EPSS

0.001

Percentile

44.4%

In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin password or make other changes.