Description
An issue was discovered in views/list.py in GNU Mailman Postorius before 1.3.5. An attacker (logged into any account) can send a crafted POST request to unsubscribe any user from a mailing list, also revealing whether that address was subscribed in the first place.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-4970-1 | postorius security update |
EUVD |
EUVD-2021-0197 | An issue was discovered in views/list.py in GNU Mailman Postorius before 1.3.5. An attacker (logged into any account) can send a crafted POST request to unsubscribe any user from a mailing list, also revealing whether that address was subscribed in the first place. |
Github GHSA |
GHSA-v83x-78q3-gr2j | GNU Mailman Postorius Access Control Issues |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T02:27:31.978Z
Reserved: 2021-08-31T00:00:00.000Z
Link: CVE-2021-40347
No data.
Status : Modified
Published: 2021-09-10T19:15:08.163
Modified: 2024-11-21T06:23:55.190
Link: CVE-2021-40347
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD
Github GHSA