suse · CVE-2021-43332

Quick triage

Priority: high Published: 2021-11-17 02:09:54 UTC Updated: 2025-02-17 00:25:06 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2021-43332 severity important: SUSE including 2 source package names (mailman-2.1.15-9.6.29.1, mailman-2.1.17-3.26.1), 17 product×package rows across 17 product lines (HPE Helion OpenStack 8, SUSE Linux Enterprise Server 11 SP3-TERADATA, … (17 product lines)): Fixed 17.

Description:

In GNU Mailman before 2.1.36, the CSRF token for the Cgi/admindb.py admindb page contains an encrypted version of the list admin password. This could potentially be cracked by a moderator via an offline brute-force attack.

cvelogic Threat Intelligence