Re: mailman 2.x: XSS via file attachments in list archives

Related Vulnerabilities: CVE-2020-12137  
                							

                <!--X-Body-Begin-->
<!--X-User-Header-->

oss-sec
mailing list archives
<!--X-User-Header-End-->
<!--X-TopPNI-->

By Date

By Thread

</form>

<!--X-TopPNI-End-->
<!--X-MsgBody-->
<!--X-Subject-Header-Begin-->
Re: mailman 2.x: XSS via file attachments in list archives

<!--X-Subject-Header-End-->
<!--X-Head-of-Message-->

From: Salvatore Bonaccorso &lt;carnil () debian org&gt;

Date: Fri, 24 Apr 2020 21:00:16 +0200

<!--X-Head-of-Message-End-->
<!--X-Head-Body-Sep-Begin-->

<!--X-Head-Body-Sep-End-->
<!--X-Body-of-Message-->
Hi,

On Thu, Apr 23, 2020 at 04:41:43PM +0200, Stefan Cornelius wrote:
On Mon, 24 Feb 2020 11:06:38 -0500
Jim Popovitch &lt;jim () k4vqc com&gt; wrote:

On Mon, 2020-02-24 at 15:34 +0100, Hanno Böck wrote:
This change is in mailman 2.1.30rc1, but not in any stable release
of mailman.  

Just for some added info, Mailman v2.1.30 is almost released, the
holdup is with some language translations.  Mailman v2.1.30 will be
the last of the Mailman v2 releases as primary development and effort
has long shifted to Mailman v3. Further, the Mailman v2 branch is
tied to Python v2, which is now EOL by the fine Python folk.

Once Mailman v2.1.30 is release, I'm sure the various distributions
will pull the commit and merge the particulars into their release
branches, and that will surely include this XSS fix. 

Hi,

It seems like this does not have a CVE? Is there a reason for this, or
did this just slip through the cracks/was never really requested?

This appears to have happened now,
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12137 was
assigned.

Regards,
Salvatore

<!--X-Body-of-Message-End-->
<!--X-MsgBody-End-->
<!--X-Follow-Ups-->

<!--X-Follow-Ups-End-->
<!--X-References-->
<!--X-References-End-->
<!--X-BotPNI-->

By Date

By Thread

Current thread:

Re: mailman 2.x: XSS via file attachments in list archives Stefan Cornelius (Apr 23)

Re: mailman 2.x: XSS via file attachments in list archives Salvatore Bonaccorso (Apr 24)

<!--X-BotPNI-End-->
<!--X-User-Footer-->
<!--X-User-Footer-End-->