VYPR
High severityNVD Advisory· Published Dec 2, 2021· Updated Aug 4, 2024

CVE-2021-44227

CVE-2021-44227

Description

In GNU Mailman before 2.1.38, a list member or moderator can obtain a CSRF token and forge admin requests to escalate privileges.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

In GNU Mailman before 2.1.38, a list member or moderator can obtain a CSRF token and forge admin requests to escalate privileges.

Vulnerability

In GNU Mailman versions prior to 2.1.38, a cross-site request forgery (CSRF) vulnerability exists. A list member or moderator can obtain a valid CSRF token from an admindb or options page and then craft a malicious POST request to the admin interface. This allows changing the list admin password or performing other administrative actions. The vulnerability is present in all versions before 2.1.38. [1], [2]

Exploitation

An attacker needs to be a list member or moderator to obtain a CSRF token from a legitimate page. They must then convince a list administrator to visit a crafted web page that submits the forged request. The attacker uses the token to impersonate the admin and submit a POST request to the admin page, e.g., to change the list admin password. [2]

Impact

If successful, the attacker can change the list admin password or other list settings, leading to unauthorized administrative access. This compromises the confidentiality and integrity of the mailing list administration. The attacker gains the ability to manage the list, potentially affecting all subscribers. [1], [2]

Mitigation

The vulnerability is fixed in GNU Mailman version 2.1.38, released on 2021-11-26. Users should upgrade to this version or later. No workarounds are documented. The fix was released as part of the normal release cycle. [2]

AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
mailmanPyPI
< 2.1.382.1.38

Affected products

16

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.