{"id":"CVE-2004-0412","aliases":["GHSA-hj4h-vqpq-95wg","PYSEC-2026-658"],"title":"Mailman Sensitive Information Disclosure","summary":"Mailman Sensitive Information Disclosure","severity":"medium","vendor":"mailman","product":"mailman","ecosystem":"pip","affected":["mailman < 2.1.5"],"patched":["mailman 2.1.5"],"published":"2022-04-29","updated":"2026-07-06","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-hj4h-vqpq-95wg","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2004-0412"},{"url":"https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=123559"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/16256"},{"url":"https://gitlab.com/mailman"},{"url":"http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000842"},{"url":"http://mail.python.org/pipermail/mailman-announce/2004-May/000072.html"},{"url":"http://marc.info/?l=bugtraq&m=109034869927955&w=2"},{"url":"http://secunia.com/advisories/11701"},{"url":"http://security.gentoo.org/glsa/glsa-200406-04.xml"},{"url":"http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:051"},{"url":"http://www.securityfocus.com/bid/10412"}],"tags":["osv","pip"],"epss":0.03008,"epssPercentile":0.86758,"ingestedAt":"2026-07-08T18:25:50.254Z","slug":"CVE-2004-0412","body":"## Overview\n\nMailman before 2.1.5 allows remote attackers to obtain user passwords via a crafted email request to the Mailman server.\n\n## Affected packages\n\n- `mailman < 2.1.5`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `mailman 2.1.5`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0.6,"exploitation":0,"ransomware":0},"changes":[]}