postorius@1.3.3 vulnerabilities

A web user interface for GNU Mailman

  • latest version

    1.3.13

  • latest non vulnerable version

  • first published

    10 years ago

  • latest version published

    4 months ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the postorius package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Information Exposure

    postorius is an A web user interface for GNU Mailman

    Affected versions of this package are vulnerable to Information Exposure via the views/list.py file. An attacker (logged into any account) can send a crafted POST request to unsubscribe any user from a mailing list, also revealing whether that address was subscribed in the first place.

    How to fix Information Exposure?

    Upgrade postorius to version 1.3.5 or higher.

    [0,1.3.5)