CVE-2021-44227 - log back

CVE-2021-44227 edited at 02 Dec 2021 08:05:23
References
+ https://mail.python.org/archives/list/mailman-announce@python.org/thread/JKRWKP4BTVLYNRXV5WU6BJATLZONX3KQ/
https://bugs.launchpad.net/mailman/+bug/1952384
https://bazaar.launchpad.net/~mailman-coders/mailman/2.1/revision/1882
CVE-2021-44227 edited at 02 Dec 2021 08:04:29
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Remote
Type
- Unknown
+ Cross-site request forgery
Description
+ In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin password or make other changes.
References
+ https://bugs.launchpad.net/mailman/+bug/1952384
+ https://bazaar.launchpad.net/~mailman-coders/mailman/2.1/revision/1882
Notes
CVE-2021-44227 created at 02 Dec 2021 08:03:07