CVE-2021-43332 log
Source |
|
Severity | Medium |
Remote | Yes |
Type | Private key recovery |
Description | In GNU Mailman before 2.1.36, the CSRF token for the Cgi/admindb.py admindb page contains an encrypted version of the list admin password. This could potentially be cracked by a moderator via an offline brute-force attack. |
Group | Package | Affected | Fixed | Severity | Status | Ticket |
---|---|---|---|---|---|---|
AVG-2552 | mailman | 2.1.35-1 | 2.1.37-1 | Medium | Fixed |