Select your cookie preferences

We use cookies and similar tools to enhance your experience, provide our services, deliver relevant advertising, and make improvements. Approved third parties also use these tools to help us deliver advertising and provide certain site features.

CVE-2021-42097

Public on 2021-10-21
Modified on 2022-01-18
Description

A Cross-Site Request Forgery (CSRF) attack can be performed in mailman due to a CSRF token bypass. CSRF tokens are not checked against the right user and a token created by one user can be used by another one to perform a request, effectively bypassing the protection provided by CSRF tokens. A remote attacker with an account on the mailman system can use this flaw to perform a CSRF attack and perform operations on behalf of the victim user.

Severity
Important
See what this means
CVSS v3 Base Score
8.0
See breakdown
Continue reading

Affected Packages

Platform Package Release Date Advisory
Amazon Linux 2 - Core mailman 2022-01-18 21:37 ALAS2-2022-1740

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
NVD CVSSv2 8.5 AV:N/AC:M/Au:S/C:C/I:C/A:C
NVD CVSSv3 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H