CVE-2020-12137
Alibaba Cloud Linux (Aliyun Linux) vulnerability analysis and mitigation

Overview

GNU Mailman 2.x before 2.1.30 contains a cross-site scripting (XSS) vulnerability identified as CVE-2020-12137. The vulnerability was discovered and reported by Hanno Boeck, with the issue being publicly disclosed in April 2020. The vulnerability affects the web archive functionality of Mailman mailing list manager installations (NVD, Debian Advisory).

Technical details

The vulnerability stems from Mailman's handling of application/octet-stream MIME parts in attachments. When processing these attachments, Mailman would save them with a .obj extension. Since many web servers don't have a MIME type configured for .obj files, the server would send the content without a MIME type header. This causes web browsers to perform MIME sniffing and potentially interpret the content as HTML if it contains HTML-like content, leading to the execution of embedded JavaScript code (OSS Security). The vulnerability has been assigned a CVSS v3.1 base score of 6.1 (Medium) with vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N (NVD).

Impact

If exploited, this vulnerability could allow attackers to perform XSS attacks against visitors of the list archives. When a user views an archived message containing a specially crafted attachment, malicious JavaScript code could be executed in their browser context, potentially leading to theft of sensitive information or session hijacking (NVD).

Mitigation and workarounds

The vulnerability was fixed in Mailman version 2.1.30 by changing the extension for scrubbed application/octet-stream MIME parts from .obj to .bin, as .bin files are typically assigned the application/octet-stream MIME type by web servers. Various Linux distributions have backported the fix to their maintained versions, including Ubuntu (1:2.1.26-1ubuntu0.1 for 18.04 LTS), Debian (1:2.1.29-1+deb10u1 for Buster), and Fedora (Ubuntu Advisory, Debian Advisory).

Additional resources


SourceThis report was generated using AI

Related Alibaba Cloud Linux (Aliyun Linux) vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-7493CRITICAL9.1
  • Rocky LinuxRocky Linux
  • idm:DL1::ipa-client-samba
NoYesSep 30, 2025
CVE-2025-9900HIGH8.8
  • Rocky LinuxRocky Linux
  • libtiff-debuginfo
NoYesSep 23, 2025
CVE-2025-58060HIGH8
  • Rocky LinuxRocky Linux
  • cups
NoYesSep 11, 2025
CVE-2025-41244HIGH7.8
  • VMware ToolsVMware Tools
  • open-vm-tools-test
NoYesSep 29, 2025
CVE-2025-40928HIGH7.5
  • Alma LinuxAlma Linux
  • libjson-xs-perl
NoYesSep 08, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management