CVE Vulnerabilities

CVE-2021-34337

Published: Apr 15, 2023 | Modified: Nov 21, 2024
CVSS 3.x
6.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
7.4 MODERATE
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM

An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ability for attackers to exploit this, but can optionally be made to listen on other interfaces.

Affected Software

Name Vendor Start Version End Version
Mailman Gnu * 3.3.5 (excluding)
Mailman3 Ubuntu bionic *
Mailman3 Ubuntu esm-apps/bionic *
Mailman3 Ubuntu esm-apps/focal *
Mailman3 Ubuntu focal *
Mailman3 Ubuntu impish *
Mailman3 Ubuntu trusty *
Mailman3 Ubuntu upstream *
Mailman3 Ubuntu xenial *

References