PT-2020-3649 · Gnu+6 · Gnu Mailman+6
Hanno Böck
·
Published
2020-04-24
·
Updated
2022-11-16
·
CVE-2020-12137
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
GNU Mailman versions 2.x through 2.1.29
GNU Mailman version 2.1.30 is not affected, but all versions prior to 2.1.30 are vulnerable.
Description
The issue is related to the handling of MIME parts in GNU Mailman, which may contribute to cross-site scripting (XSS) attacks against visitors of list archives. This occurs because an HTTP reply from an archive web server may lack a MIME type, leading a web browser to perform MIME sniffing and potentially execute JavaScript code. The vulnerability is also related to the lack of protection for the web page structure, which could allow a remote attacker to impact data integrity.
Recommendations
For GNU Mailman versions 2.x through 2.1.29, update to version 2.1.30 or later to resolve the issue.
As a temporary workaround, consider restricting access to list archives to minimize the risk of exploitation.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Centos
Gnu Mailman
Linuxmint
Red Hat
Suse
Ubuntu