CVE-2021-43332 log
| Source |
|
| Severity | Medium |
| Remote | Yes |
| Type | Private key recovery |
| Description | In GNU Mailman before 2.1.36, the CSRF token for the Cgi/admindb.py admindb page contains an encrypted version of the list admin password. This could potentially be cracked by a moderator via an offline brute-force attack. |
| Group | Package | Affected | Fixed | Severity | Status | Ticket |
|---|---|---|---|---|---|---|
| AVG-2552 | mailman | 2.1.35-1 | 2.1.37-1 | Medium | Fixed |