CVE-2021-42097
published 2021-10-21CVE-2021-42097: GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain a value…
PriorityP341high8CVSS 3.1
AVNACLPRLUIRSUCHIHAH
EPSS
1.29%
66.8th percentile
GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain a value within the context of an unprivileged user account, and then use that value in a CSRF attack against an admin (e.g., for account takeover).
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| gnu | mailman | < 2.1.35 | 2.1.35 |
| gnu | mailman | >= 0 < 1:2.1.26-1ubuntu0.4 | 1:2.1.26-1ubuntu0.4 |
| gnu | mailman | >= 0 < 1:2.1.29-1ubuntu3.1 | 1:2.1.29-1ubuntu3.1 |
| gnu | mailman | >= 0 < 1:2.1.20-1ubuntu0.6+esm1 | 1:2.1.20-1ubuntu0.6+esm1 |
CVSS provenance
nvdv3.18.0HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv2.08.5HIGHAV:N/AC:M/Au:S/C:C/I:C/A:C
osv8.0HIGH
vendor_redhat8.0HIGH
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vj65-f4hc-r425: GNU Mailman before 2
ghsa_unreviewed·2022-05-24
CVE-2021-42097 [HIGH] CWE-352 GHSA-vj65-f4hc-r425: GNU Mailman before 2
GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain a value within the context of an unprivileged user account, and then use that value in a CSRF attack against an admin (e.g., for account takeover).
OSV
mailman vulnerabilities
osv·2021-11-01·CVSS 6.5
CVE-2020-12108 [MEDIUM] mailman vulnerabilities
mailman vulnerabilities
USN-5009-1 fixed vulnerabilities in Mailman. This update provides the
corresponding updates for Ubuntu 20.04 LTS. In addition, the following CVEs
were fixed:
It was discovered that Mailman allows arbitrary content injection. An attacker
could use this to inject malicious content. (CVE-2020-12108, CVE-2020-15011)
It was discovered that Mailman improperly sanitize the MIME content. An
attacker could obtain sensitive information by sending a special type of
attachment. (CVE-2020-12137)
Original advisory details:
Andre Protas, Richard Cloke, and Andy Nuttall discovered that Mailman
did not properly associate cross-site request forgery (CSRF) tokens
to specific accounts. A remote attacker could use this to perform a
CSRF attack to gain access to another account. (CV
OSV
mailman vulnerabilities
osv·2021-10-22·CVSS 4.3
CVE-2021-42097 [MEDIUM] mailman vulnerabilities
mailman vulnerabilities
Andre Protas, Richard Cloke, and Andy Nuttall discovered that Mailman
did not properly associate cross-site request forgery (CSRF) tokens
to specific accounts. A remote attacker could use this to perform a
CSRF attack to gain access to another account. (CVE-2021-42097)
Andre Protas, Richard Cloke, and Andy Nuttall discovered that Mailman's
cross-site request forgery (CSRF) tokens for the options page are
derived from the admin password. A remote attacker could possibly use
this to assist in performing a brute force attack against the admin
password. (CVE-2021-42096)
OSV
CVE-2021-42097: GNU Mailman before 2
osv·2021-10-21·CVSS 8.0
CVE-2021-42097 [HIGH] CVE-2021-42097: GNU Mailman before 2
GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain a value within the context of an unprivileged user account, and then use that value in a CSRF attack against an admin (e.g., for account takeover).
Ubuntu
Mailman vulnerabilities
vendor_ubuntu·2021-11-01·CVSS 6.5
CVE-2020-12108 [MEDIUM] Mailman vulnerabilities
Title: Mailman vulnerabilities
Summary: Several security issues were fixed in Mailman.
USN-5009-1 fixed vulnerabilities in Mailman. This update provides the
corresponding updates for Ubuntu 20.04 LTS. In addition, the following CVEs
were fixed:
It was discovered that Mailman allows arbitrary content injection. An attacker
could use this to inject malicious content. (CVE-2020-12108, CVE-2020-15011)
It was discovered that Mailman improperly sanitize the MIME content. An
attacker could obtain sensitive information by sending a special type of
attachment. (CVE-2020-12137)
Original advisory details:
Andre Protas, Richard Cloke, and Andy Nuttall discovered that Mailman
did not properly associate cross-site request forgery (CSRF) tokens
to specific accounts. A remote attacker could use this
Ubuntu
Mailman vulnerabilities
vendor_ubuntu·2021-10-22·CVSS 4.3
CVE-2021-42096 [MEDIUM] Mailman vulnerabilities
Title: Mailman vulnerabilities
Summary: Several security issues were fixed in Mailman.
Andre Protas, Richard Cloke, and Andy Nuttall discovered that Mailman
did not properly associate cross-site request forgery (CSRF) tokens
to specific accounts. A remote attacker could use this to perform a
CSRF attack to gain access to another account. (CVE-2021-42097)
Andre Protas, Richard Cloke, and Andy Nuttall discovered that Mailman's
cross-site request forgery (CSRF) tokens for the options page are
derived from the admin password. A remote attacker could possibly use
this to assist in performing a brute force attack against the admin
password. (CVE-2021-42096)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
mailman: CSRF token bypass allows to perform CSRF attacks and account takeover
vendor_redhat·2021-10-21·CVSS 8.0
CVE-2021-42097 [HIGH] CWE-352 mailman: CSRF token bypass allows to perform CSRF attacks and account takeover
mailman: CSRF token bypass allows to perform CSRF attacks and account takeover
GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain a value within the context of an unprivileged user account, and then use that value in a CSRF attack against an admin (e.g., for account takeover).
A Cross-Site Request Forgery (CSRF) attack can be performed in mailman due to a CSRF token bypass. CSRF tokens are not checked against the right user and a token created by one user can be used by another one to perform a request, effectively bypassing the protection provided by CSRF tokens. A remote attacker with an account on the mailman system can use this flaw to perform a CSRF attack and perform operations on beha
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2021/10/21/4https://bugs.launchpad.net/mailman/+bug/1947640https://mail.python.org/archives/list/mailman-announce%40python.org/thread/IKCO6JU755AP5G5TKMBJL6IEZQTTNPDQ/https://www.debian.org/security/2021/dsa-4991http://www.openwall.com/lists/oss-security/2021/10/21/4https://bugs.launchpad.net/mailman/+bug/1947640https://mail.python.org/archives/list/mailman-announce%40python.org/thread/IKCO6JU755AP5G5TKMBJL6IEZQTTNPDQ/https://www.debian.org/security/2021/dsa-4991
2021-10-21
Published