CVE-2021-44227
Description
In GNU Mailman before 2.1.38, a list member or moderator can obtain a CSRF token and forge admin requests to escalate privileges.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
In GNU Mailman before 2.1.38, a list member or moderator can obtain a CSRF token and forge admin requests to escalate privileges.
Vulnerability
In GNU Mailman versions prior to 2.1.38, a cross-site request forgery (CSRF) vulnerability exists. A list member or moderator can obtain a valid CSRF token from an admindb or options page and then craft a malicious POST request to the admin interface. This allows changing the list admin password or performing other administrative actions. The vulnerability is present in all versions before 2.1.38. [1], [2]
Exploitation
An attacker needs to be a list member or moderator to obtain a CSRF token from a legitimate page. They must then convince a list administrator to visit a crafted web page that submits the forged request. The attacker uses the token to impersonate the admin and submit a POST request to the admin page, e.g., to change the list admin password. [2]
Impact
If successful, the attacker can change the list admin password or other list settings, leading to unauthorized administrative access. This compromises the confidentiality and integrity of the mailing list administration. The attacker gains the ability to manage the list, potentially affecting all subscribers. [1], [2]
Mitigation
The vulnerability is fixed in GNU Mailman version 2.1.38, released on 2021-11-26. Users should upgrade to this version or later. No workarounds are documented. The fix was released as part of the normal release cycle. [2]
AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mailmanPyPI | < 2.1.38 | 2.1.38 |
Affected products
16- GNU/Mailmandescription
- ghsa-coords15 versionspkg:pypi/mailmanpkg:rpm/almalinux/mailmanpkg:rpm/suse/mailman&distro=HPE%20Helion%20OpenStack%208pkg:rpm/suse/mailman&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/mailman&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-BCLpkg:rpm/suse/mailman&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-LTSSpkg:rpm/suse/mailman&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-LTSSpkg:rpm/suse/mailman&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/mailman&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/mailman&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/mailman&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/mailman&distro=SUSE%20OpenStack%20Cloud%208pkg:rpm/suse/mailman&distro=SUSE%20OpenStack%20Cloud%209pkg:rpm/suse/mailman&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208pkg:rpm/suse/mailman&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209
< 2.1.38+ 14 more
- (no CPE)range: < 2.1.38
- (no CPE)range: < 3:2.1.29-12.module_el8.5.0+26+48d4c9ee.2
- (no CPE)range: < 2.1.17-3.26.1
- (no CPE)range: < 2.1.17-3.26.1
- (no CPE)range: < 2.1.17-3.26.1
- (no CPE)range: < 2.1.17-3.26.1
- (no CPE)range: < 2.1.17-3.26.1
- (no CPE)range: < 2.1.17-3.26.1
- (no CPE)range: < 2.1.17-3.26.1
- (no CPE)range: < 2.1.17-3.26.1
- (no CPE)range: < 2.1.17-3.26.1
- (no CPE)range: < 2.1.17-3.26.1
- (no CPE)range: < 2.1.17-3.26.1
- (no CPE)range: < 2.1.17-3.26.1
- (no CPE)range: < 2.1.17-3.26.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/advisories/GHSA-xq58-69h2-765mghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-44227ghsaADVISORY
- bugs.launchpad.net/mailman/+bug/1952384ghsax_refsource_MISCWEB
- lists.debian.org/debian-lts-announce/2022/06/msg00011.htmlghsamailing-listx_refsource_MLISTWEB
News mentions
0No linked articles in our index yet.