CVE-2021-42096
Alma Linux vulnerability analysis and mitigation

Overview

CVE-2021-42096 affects GNU Mailman versions before 2.1.35, discovered in October 2021. This vulnerability is related to the CSRF (Cross-site Request Forgery) token implementation in the mailing list management system, where the token is derived from the admin password and exposed to unprivileged list members (Python Announce, NVD).

Technical details

The vulnerability stems from the implementation where the CSRF token generated for the options page is derived from the hashed list admin password. This design flaw exposes sensitive information to unprivileged members of a list, as the token contains information derived from the admin password hash (Red Hat CVE).

Impact

The vulnerability could potentially allow a list member to discover the list administrator's password through offline brute-force attacks. However, this attack can only be carried out by list members and may not be of significant concern for sites with only trusted list members (Python Announce).

Mitigation and workarounds

The vulnerability was fixed in GNU Mailman version 2.1.35. System administrators are advised to upgrade to this version or apply the available security patch. For those who don't want to upgrade, a patch was made available at the Launchpad bug tracker (Python Announce).

Additional resources


SourceThis report was generated using AI

Related Alma Linux vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-66287HIGH8.8
  • Alma LinuxAlma Linux
  • webkitgtk-doc
NoYesDec 04, 2025
CVE-2025-13502HIGH7.5
  • Alma LinuxAlma Linux
  • javascriptcoregtk6.0
NoYesNov 25, 2025
CVE-2025-13947HIGH7.4
  • Alma LinuxAlma Linux
  • webkitgtk6.0
NoYesDec 03, 2025
CVE-2025-64505MEDIUM6.1
  • NixOSNixOS
  • java-17-openjdk-headless
NoYesNov 25, 2025
CVE-2025-40185N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-modules-partner
NoYesNov 12, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management