CVE-2021-42096
published 2021-10-21CVE-2021-42096: GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A certain csrf_token value is derived from the admin password, and may be useful in conducting…
PriorityP425medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
1.21%
65.3th percentile
GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A certain csrf_token value is derived from the admin password, and may be useful in conducting a brute-force attack against that password.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| gnu | mailman | < 2.1.35 | 2.1.35 |
| gnu | mailman | >= 0 < 1:2.1.26-1ubuntu0.4 | 1:2.1.26-1ubuntu0.4 |
| gnu | mailman | >= 0 < 1:2.1.29-1ubuntu3.1 | 1:2.1.29-1ubuntu3.1 |
| gnu | mailman | >= 0 < 1:2.1.20-1ubuntu0.6+esm1 | 1:2.1.20-1ubuntu0.6+esm1 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv6.5MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c875-cgwj-4fjw: GNU Mailman before 2
ghsa_unreviewed·2022-05-24
CVE-2021-42096 [MEDIUM] CWE-307 GHSA-c875-cgwj-4fjw: GNU Mailman before 2
GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A certain csrf_token value is derived from the admin password, and may be useful in conducting a brute-force attack against that password.
OSV
mailman vulnerabilities
osv·2021-11-01·CVSS 6.5
CVE-2020-12108 [MEDIUM] mailman vulnerabilities
mailman vulnerabilities
USN-5009-1 fixed vulnerabilities in Mailman. This update provides the
corresponding updates for Ubuntu 20.04 LTS. In addition, the following CVEs
were fixed:
It was discovered that Mailman allows arbitrary content injection. An attacker
could use this to inject malicious content. (CVE-2020-12108, CVE-2020-15011)
It was discovered that Mailman improperly sanitize the MIME content. An
attacker could obtain sensitive information by sending a special type of
attachment. (CVE-2020-12137)
Original advisory details:
Andre Protas, Richard Cloke, and Andy Nuttall discovered that Mailman
did not properly associate cross-site request forgery (CSRF) tokens
to specific accounts. A remote attacker could use this to perform a
CSRF attack to gain access to another account. (CV
OSV
mailman vulnerabilities
osv·2021-10-22·CVSS 4.3
CVE-2021-42097 [MEDIUM] mailman vulnerabilities
mailman vulnerabilities
Andre Protas, Richard Cloke, and Andy Nuttall discovered that Mailman
did not properly associate cross-site request forgery (CSRF) tokens
to specific accounts. A remote attacker could use this to perform a
CSRF attack to gain access to another account. (CVE-2021-42097)
Andre Protas, Richard Cloke, and Andy Nuttall discovered that Mailman's
cross-site request forgery (CSRF) tokens for the options page are
derived from the admin password. A remote attacker could possibly use
this to assist in performing a brute force attack against the admin
password. (CVE-2021-42096)
OSV
CVE-2021-42096: GNU Mailman before 2
osv·2021-10-21·CVSS 4.3
CVE-2021-42096 [MEDIUM] CVE-2021-42096: GNU Mailman before 2
GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A certain csrf_token value is derived from the admin password, and may be useful in conducting a brute-force attack against that password.
Ubuntu
Mailman vulnerabilities
vendor_ubuntu·2021-11-01·CVSS 6.5
CVE-2020-12108 [MEDIUM] Mailman vulnerabilities
Title: Mailman vulnerabilities
Summary: Several security issues were fixed in Mailman.
USN-5009-1 fixed vulnerabilities in Mailman. This update provides the
corresponding updates for Ubuntu 20.04 LTS. In addition, the following CVEs
were fixed:
It was discovered that Mailman allows arbitrary content injection. An attacker
could use this to inject malicious content. (CVE-2020-12108, CVE-2020-15011)
It was discovered that Mailman improperly sanitize the MIME content. An
attacker could obtain sensitive information by sending a special type of
attachment. (CVE-2020-12137)
Original advisory details:
Andre Protas, Richard Cloke, and Andy Nuttall discovered that Mailman
did not properly associate cross-site request forgery (CSRF) tokens
to specific accounts. A remote attacker could use this
Ubuntu
Mailman vulnerabilities
vendor_ubuntu·2021-10-22·CVSS 4.3
CVE-2021-42096 [MEDIUM] Mailman vulnerabilities
Title: Mailman vulnerabilities
Summary: Several security issues were fixed in Mailman.
Andre Protas, Richard Cloke, and Andy Nuttall discovered that Mailman
did not properly associate cross-site request forgery (CSRF) tokens
to specific accounts. A remote attacker could use this to perform a
CSRF attack to gain access to another account. (CVE-2021-42097)
Andre Protas, Richard Cloke, and Andy Nuttall discovered that Mailman's
cross-site request forgery (CSRF) tokens for the options page are
derived from the admin password. A remote attacker could possibly use
this to assist in performing a brute force attack against the admin
password. (CVE-2021-42096)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
mailman: CSRF token derived from admin password allows offline brute-force attack
vendor_redhat·2021-10-21·CVSS 4.3
CVE-2021-42096 [MEDIUM] CWE-200 mailman: CSRF token derived from admin password allows offline brute-force attack
mailman: CSRF token derived from admin password allows offline brute-force attack
GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A certain csrf_token value is derived from the admin password, and may be useful in conducting a brute-force attack against that password.
Sensitive information is exposed to unprivileged users in mailman. The hash of the list admin password is used to derive the CSRF (Cross-site Request Forgery) token, which is exposed to unprivileged members of a list. Malicious members may use the CSRF token to perform an offline brute-force attack to retrieve the list admin password.
Statement: This issue did not affect the versions of mailman as shipped with Red Hat Enterprise Linux 6, and 7 as they did not use CSRF tokens in members pages.
Package: mai
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2021/10/21/4https://bugs.launchpad.net/mailman/+bug/1947639https://mail.python.org/archives/list/mailman-announce%40python.org/thread/IKCO6JU755AP5G5TKMBJL6IEZQTTNPDQ/https://www.debian.org/security/2021/dsa-4991http://www.openwall.com/lists/oss-security/2021/10/21/4https://bugs.launchpad.net/mailman/+bug/1947639https://mail.python.org/archives/list/mailman-announce%40python.org/thread/IKCO6JU755AP5G5TKMBJL6IEZQTTNPDQ/https://www.debian.org/security/2021/dsa-4991
2021-10-21
Published