Medium severity5.4NVD Advisory· Published Sep 10, 2021· Updated Jun 17, 2026
CVE-2021-40347
CVE-2021-40347
Description
An issue was discovered in views/list.py in GNU Mailman Postorius before 1.3.5. An attacker (logged into any account) can send a crafted POST request to unsubscribe any user from a mailing list, also revealing whether that address was subscribed in the first place.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
postoriusPyPI | < 1.3.5 | 1.3.5 |
Affected products
3- GNU Mailman/Postoriusdescription
Patches
Vulnerability mechanics
References
9- gitlab.com/mailman/postorius/-/commit/3d880c56b58bc26b32eac0799407d74b64b7474bnvdPatchThird Party AdvisoryWEB
- gitlab.com/mailman/postorius/-/issues/531nvdExploitIssue TrackingPatchThird Party AdvisoryWEB
- phabricator.wikimedia.org/T289798nvdExploitPatchThird Party AdvisoryWEB
- bugs.debian.org/cgi-bin/bugreport.cginvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-v83x-78q3-gr2jghsaADVISORY
- gitlab.com/mailman/postorius/-/tagsnvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-40347ghsaADVISORY
- www.debian.org/security/2021/dsa-4970nvdThird Party AdvisoryWEB
- github.com/pypa/advisory-database/tree/main/vulns/postorius/PYSEC-2021-319.yamlghsaWEB
News mentions
0No linked articles in our index yet.