UBUNTU-CVE-2021-43332
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-43332
UBUNTU-CVE-2021-43332
Summary:
Details: In GNU Mailman before 2.1.36, the CSRF token for the Cgi/admindb.py admindb page contains an encrypted version of the list admin password. This could potentially be cracked by a moderator via an offline brute-force attack.
References: https://ubuntu.com/security/CVE-2021-43332, https://mail.python.org/archives/list/[email protected]/message/I2X7PSFXIEPLM3UMKZMGOEO3UFYETGRL/, https://bugs.launchpad.net/mailman/+bug/1949403, https://ubuntu.com/security/notices/USN-5151-1, https://ubuntu.com/security/notices/USN-5151-2, https://www.cve.org/CVERecord?id=CVE-2021-43332
Affected packages
Package
Name: mailman
Purl: pkg:deb/ubuntu/mailman@1:2.1.20-1ubuntu0.6+esm2?arch=source&distro=esm-infra/xenial
Affected ranges
Type: ECOSYSTEM
Events:
