CVE-2021-40347 - log back

CVE-2021-40347 edited at 10 Sep 2021 21:11:19
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Remote
Type
- Unknown
+ Denial of service
Description
+ An issue was discovered in views/list.py in GNU Mailman Postorius before 1.3.5. An attacker (logged into any account) can send a crafted POST request to unsubscribe any user from a mailing list, also revealing whether that address was subscribed in the first place.
References
+ https://gitlab.com/mailman/postorius/-/issues/531
+ https://phabricator.wikimedia.org/T289798
+ https://gitlab.com/mailman/postorius/-/commit/0de3cdcdad974af76a9e197d2b9a46dfb2303bc8
Notes
CVE-2021-40347 created at 10 Sep 2021 21:08:44