|
|
Message-ID: <875x4zk7k4.fsf@alyssa.is>
Date: Thu, 07 May 2026 09:22:35 +0200
From: Alyssa Ross <hi@...ssa.is>
To: oss-security@...ts.openwall.com
Subject: XSS in Postorius (Mailman 3) 1.3.13 and earlier
The current released version of Postorius, and earlier versions, contain
an XSS vulnerability in the admin UI. A fix was merged upstream in
January 2025, which included documentation of the security issue in the
news file[1], but no release has been made since, and I don't see any
previous discussion in the oss-security archives. Distributions
packaging the latest release that have not backported this fix are
vulnerable. I have heard that this issue is being actively exploited.
[1]: https://gitlab.com/mailman/postorius/-/commit/c4706abd05ba6bcf472fc674b160d3a9d6a4868b
Download attachment "signature.asc" of type "application/pgp-signature" (228 bytes)
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.