Related Vulnerabilities: CVE-2021-44227  

In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin password or make other changes.

Severity Medium

Remote Yes

Type Cross-site request forgery

Description

In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin password or make other changes.

AVG-2598 mailman 2.1.37-1 2.1.38-1 Medium Fixed

https://mail.python.org/archives/list/mailman-announce@python.org/thread/JKRWKP4BTVLYNRXV5WU6BJATLZONX3KQ/
https://bugs.launchpad.net/mailman/+bug/1952384
https://bazaar.launchpad.net/~mailman-coders/mailman/2.1/revision/1882