SUSE-SU-2022:1886-1
Dashboard / Vulnerabilities / SUSE-SU-2022:1886-1
SUSE-SU-2022:1886-1
Summary: Security update for mailman
Details: This update for mailman fixes the following issues: - CVE-2021-44227: Preventing list moderator or list member accessing the admin UI (bsc#1193316). - CVE-2021-43332: Preventing list moderator from cracking the list admin password encrypted in a CSRF token (bsc#1192741). - CVE-2021-43331: Fixed XSS in Cgi/options.py (bsc#1192735). - CVE-2021-42096: Add protection against remote privilege escalation via csrf_token derived from admin password (bsc#1191959).
References: https://www.suse.com/support/update/announcement/2022/suse-su-20221886-1/, https://bugzilla.suse.com/1191959, https://bugzilla.suse.com/1192735, https://bugzilla.suse.com/1192741, https://bugzilla.suse.com/1193316, https://www.suse.com/security/cve/CVE-2021-42096, https://www.suse.com/security/cve/CVE-2021-43331, https://www.suse.com/security/cve/CVE-2021-43332, https://www.suse.com/security/cve/CVE-2021-44227
Affected packages
Package
Name: mailman
Purl: pkg:rpm/suse/mailman&distro=HPE%20Helion%20OpenStack%208
Affected ranges
Type: ECOSYSTEM
Events:
