[Mailman-Users] Re: Mailman-2.1.x vulnerabilities found

2025-04-29 Thread Mark Sapiro
On 4/29/25 06:31, Ralf Hildebrandt via Mailman-Users wrote: Just received word about those three: https://github.com/0NYX-MY7H/CVE-2025-43921 -- wasn't able to reproduce on 2.1.39 https://github.com/0NYX-MY7H/CVE-2025-43920 -- wasn't able to reproduce on 2.1.39, due to not using an *_EXTERNAL_A

[Mailman-Users] Re: Mailman-2.1.x vulnerabilities found

2025-04-29 Thread Matthew Pounsett
On Tue, Apr 29, 2025 at 9:32 AM Ralf Hildebrandt via Mailman-Users < mailman-users@python.org> wrote: > Just received word about those three: > > https://github.com/0NYX-MY7H/CVE-2025-43921 > -- wasn't able to reproduce on 2.1.39 > Same for me. All this "exploit" gets me is the list creation pag

[Mailman-Users] Mailman-2.1.x vulnerabilities found

2025-04-29 Thread Ralf Hildebrandt via Mailman-Users
Just received word about those three: https://github.com/0NYX-MY7H/CVE-2025-43921 -- wasn't able to reproduce on 2.1.39 https://github.com/0NYX-MY7H/CVE-2025-43920 -- wasn't able to reproduce on 2.1.39, due to not using an *_EXTERNAL_ARCHIVER https://github.com/0NYX-MY7H/CVE-2025-43919 -- wasn't