/srv/irclogs.ubuntu.com/2021/11/03/#ubuntu-security.txt

=== cpaelzer_ is now known as cpaelzer
sarnoldfungi: https://ubuntu.com/security/CVE-2021-42097 now shows the correct status :) thanks for the report20:36
ubottuGNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain a value within the context of an unprivileged user account, and then use that value in a CSRF attack against an admin (e.g., for account takeover). <https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-42097>20:36
fungisarnold: yep, noticed that earlier today. thanks again for all the hard work!21:00
sarnoldfungi: woot :) it was all others, not me, I'm just pushing buttons :)21:01
fungieven tracking these things is work ;)21:02
=== LordOfThePings is now known as Hash

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!