CVE-2021-42097 log
Source |
|
Severity | Medium |
Remote | Yes |
Type | Cross-site request forgery |
Description | GNU Mailman before 2.1.35 may allow remote privilege escalation. A csrf_token value is not specific to a single user account. An attacker can obtain a value within the context of an unprivileged user account, and then use that value in a CSRF attack against an admin (e.g., for account takeover). |
Group | Package | Affected | Fixed | Severity | Status | Ticket |
---|---|---|---|---|---|---|
AVG-2485 | mailman | 2.1.34-2 | 2.1.35-1 | Medium | Fixed |