PyPI package
mailman
pkg:pypi/mailman
Vulnerabilities (6)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2021-34337 | — | < 3.3.5 | 3.3.5 | Apr 15, 2023 | An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ab | ||
| CVE-2021-44227 | — | < 2.1.38 | 2.1.38 | Dec 2, 2021 | In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin password or make other changes. | ||
| CVE-2018-13796 | — | < 2.1.28 | 2.1.28 | Jul 12, 2018 | An issue was discovered in GNU Mailman before 2.1.28. A crafted URL can cause arbitrary text to be displayed on a web page from a trusted site. | ||
| CVE-2004-1177 | — | < 2.1.5 | 2.1.5 | Jan 10, 2005 | Cross-site scripting (XSS) vulnerability in the driver script in mailman before 2.1.5 allows remote attackers to inject arbitrary web script or HTML via a URL, which is not properly escaped in the resulting error page. | ||
| CVE-2004-0412 | — | < 2.1.5 | 2.1.5 | Aug 18, 2004 | Mailman before 2.1.5 allows remote attackers to obtain user passwords via a crafted email request to the Mailman server. | ||
| CVE-2003-0038 | — | < 2.1.1 | 2.1.1 | Feb 7, 2003 | Cross-site scripting (XSS) vulnerability in options.py for Mailman 2.1 allows remote attackers to inject script or HTML into web pages via the (1) email or (2) language parameters. |
- CVE-2021-34337Apr 15, 2023affected < 3.3.5fixed 3.3.5
An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ab
- CVE-2021-44227Dec 2, 2021affected < 2.1.38fixed 2.1.38
In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin password or make other changes.
- CVE-2018-13796Jul 12, 2018affected < 2.1.28fixed 2.1.28
An issue was discovered in GNU Mailman before 2.1.28. A crafted URL can cause arbitrary text to be displayed on a web page from a trusted site.
- CVE-2004-1177Jan 10, 2005affected < 2.1.5fixed 2.1.5
Cross-site scripting (XSS) vulnerability in the driver script in mailman before 2.1.5 allows remote attackers to inject arbitrary web script or HTML via a URL, which is not properly escaped in the resulting error page.
- CVE-2004-0412Aug 18, 2004affected < 2.1.5fixed 2.1.5
Mailman before 2.1.5 allows remote attackers to obtain user passwords via a crafted email request to the Mailman server.
- CVE-2003-0038Feb 7, 2003affected < 2.1.1fixed 2.1.1
Cross-site scripting (XSS) vulnerability in options.py for Mailman 2.1 allows remote attackers to inject script or HTML into web pages via the (1) email or (2) language parameters.