CVE-2016-6893
published 2016-09-02CVE-2016-6893: Cross-site request forgery (CSRF) vulnerability in the user options page in GNU Mailman 2.1.x before 2.1.23 allows remote attackers to hijack the…
PriorityP342high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
1.61%
73.1th percentile
Cross-site request forgery (CSRF) vulnerability in the user options page in GNU Mailman 2.1.x before 2.1.23 allows remote attackers to hijack the authentication of arbitrary users for requests that modify an option, as demonstrated by gaining access to the credentials of a victim's account.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Mailman vulnerabilities
vendor_ubuntu·2016-11-01·CVSS 8.8
CVE-2016-6893 [HIGH] Mailman vulnerabilities
Title: Mailman vulnerabilities
Summary: Several security issues were fixed in Mailman.
It was discovered that the Mailman administrative web interface did not
protect against cross-site request forgery (CSRF) attacks. If an
authenticated user were tricked into visiting a malicious website while
logged into Mailman, a remote attacker could perform administrative
actions. This issue only affected Ubuntu 12.04 LTS. (CVE-2016-7123)
Nishant Agarwala discovered that the Mailman user options page did not
protect against cross-site request forgery (CSRF) attacks. If an
authenticated user were tricked into visiting a malicious website while
logged into Mailman, a remote attacker could modify user options.
(CVE-2016-6893)
Instructions: In general, a standard system update will make all the neces
Red Hat
mailman: CSRF protection missing in the user options page
vendor_redhat·2016-08-19·CVSS 8.8
CVE-2016-6893 [HIGH] CWE-352 mailman: CSRF protection missing in the user options page
mailman: CSRF protection missing in the user options page
Cross-site request forgery (CSRF) vulnerability in the user options page in GNU Mailman 2.1.x before 2.1.23 allows remote attackers to hijack the authentication of arbitrary users for requests that modify an option, as demonstrated by gaining access to the credentials of a victim's account.
Package: mailman (Red Hat Enterprise Linux 5) - Will not fix
Package: mailman (Red Hat Enterprise Linux 6) - Will not fix
GHSA
GHSA-46p3-9vjv-gq2w: Cross-site request forgery (CSRF) vulnerability in the user options page in GNU Mailman 2
ghsa_unreviewed·2022-05-17
CVE-2016-6893 [HIGH] CWE-352 GHSA-46p3-9vjv-gq2w: Cross-site request forgery (CSRF) vulnerability in the user options page in GNU Mailman 2
Cross-site request forgery (CSRF) vulnerability in the user options page in GNU Mailman 2.1.x before 2.1.23 allows remote attackers to hijack the authentication of arbitrary users for requests that modify an option, as demonstrated by gaining access to the credentials of a victim's account.
OSV
mailman vulnerabilities
osv·2016-11-01·CVSS 8.8
CVE-2016-7123 [HIGH] mailman vulnerabilities
mailman vulnerabilities
It was discovered that the Mailman administrative web interface did not
protect against cross-site request forgery (CSRF) attacks. If an
authenticated user were tricked into visiting a malicious website while
logged into Mailman, a remote attacker could perform administrative
actions. This issue only affected Ubuntu 12.04 LTS. (CVE-2016-7123)
Nishant Agarwala discovered that the Mailman user options page did not
protect against cross-site request forgery (CSRF) attacks. If an
authenticated user were tricked into visiting a malicious website while
logged into Mailman, a remote attacker could modify user options.
(CVE-2016-6893)
OSV
CVE-2016-6893: Cross-site request forgery (CSRF) vulnerability in the user options page in GNU Mailman 2
osv·2016-09-02·CVSS 8.8
CVE-2016-6893 [HIGH] CVE-2016-6893: Cross-site request forgery (CSRF) vulnerability in the user options page in GNU Mailman 2
Cross-site request forgery (CSRF) vulnerability in the user options page in GNU Mailman 2.1.x before 2.1.23 allows remote attackers to hijack the authentication of arbitrary users for requests that modify an option, as demonstrated by gaining access to the credentials of a victim's account.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-6893 mailman: CSRF protection missing in the user options page [fedora-all]
bugzilla·2016-08-25·CVSS 8.8
CVE-2016-6893 [HIGH] CVE-2016-6893 mailman: CSRF protection missing in the user options page [fedora-all]
CVE-2016-6893 mailman: CSRF protection missing in the user options page [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versi
Bugzilla
CVE-2016-6893 mailman: CSRF protection missing in the user options page
bugzilla·2016-08-25·CVSS 8.8
CVE-2016-6893 [HIGH] CVE-2016-6893 mailman: CSRF protection missing in the user options page
CVE-2016-6893 mailman: CSRF protection missing in the user options page
A CSRF vulnerability was found in mailman's user options page. This could conceivably allow an attacker to obtain a user's password.
References:
https://mail.python.org/pipermail/mailman-announce/2016-August/000225.html
Discussion:
Created mailman tracking bugs for this issue:
Affects: fedora-all [bug 1370156]
---
Upstream patch:
https://mail.python.org/pipermail/mailman-announce/2016-August/000226.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2021:4913 https://access.redhat.com/errata/RHSA-2021:4913
http://www.debian.org/security/2016/dsa-3668http://www.securityfocus.com/bid/92731http://www.securitytracker.com/id/1036728https://bugs.launchpad.net/bugs/1614841http://www.debian.org/security/2016/dsa-3668http://www.securityfocus.com/bid/92731http://www.securitytracker.com/id/1036728https://bugs.launchpad.net/bugs/1614841
2016-09-02
Published