{"id":"CVE-2021-44227","title":"mailman: CSRF token bypass allows to perform CSRF attacks and admin takeover (CVE-2021-44227)","summary":"A Cross-Site Request Forgery (CSRF) attack can be performed in mailman due to a CSRF token bypass. CSRF tokens are not checked against the right type of user when performing admin operations and a token created by a regular user can be use…","severity":"high","cvss":8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","cvssSource":"vendor","cwe":"CWE-352","vendor":"Red Hat","product":"Red Hat Enterprise Linux AppStream EUS (v. 8.2)","affected":["enterprise_linux 6","enterprise_linux_server_v_7","enterprise_linux_workstation_v_7","enterprise_linux_appstream_e4s_v_8_1","enterprise_linux_appstream_eus_v_8_2","enterprise_linux_appstream_eus_v_8_4","enterprise_linux_appstream_v_8"],"patched":["enterprise_linux_server_v_7","enterprise_linux_workstation_v_7","enterprise_linux_appstream_e4s_v_8_1","enterprise_linux_appstream_eus_v_8_2","enterprise_linux_appstream_eus_v_8_4","enterprise_linux_appstream_v_8"],"published":"2021-11-26","updated":"2026-09-07","sourceUpdated":"2026-09-07T16:51:02+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-44227.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-44227.json"},{"url":"https://access.redhat.com/security/cve/CVE-2021-44227"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2026862"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-44227"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-44227"},{"url":"https://access.redhat.com/errata/RHSA-2021:4913"},{"url":"https://access.redhat.com/errata/RHSA-2021:5081"},{"url":"https://access.redhat.com/errata/RHSA-2021:5080"},{"url":"https://access.redhat.com/errata/RHSA-2021:4915"},{"url":"https://access.redhat.com/errata/RHSA-2021:4916"},{"url":"https://bugs.launchpad.net/mailman/+bug/1952384"},{"url":"https://gitlab.com/mailman/mailman"},{"url":"https://lists.debian.org/debian-lts-announce/2022/06/msg00011.html"}],"tags":["csaf","vex","red-hat","osv","pip"],"epss":0.00733,"epssPercentile":0.52332,"aliases":["GHSA-xq58-69h2-765m","PYSEC-2026-660"],"ecosystem":"pip","ingestedAt":"2026-07-08T18:25:54.470Z","slug":"CVE-2021-44227","body":"## Overview\n\nA Cross-Site Request Forgery (CSRF) attack can be performed in mailman due to a CSRF token bypass. CSRF tokens are not checked against the right type of user when performing admin operations and a token created by a regular user can be used by an admin to perform an admin-level request, effectively bypassing the protection provided by CSRF tokens. A remote attacker with an account on the mailman system can use this flaw to perform a CSRF attack and perform operations on behalf of the victim admin.\n\n## Vendor advisories\n\n- **RHSA-2021:4913** · Red Hat · fixed in: Red Hat Enterprise Linux Server (v. 7), Red Hat Enterprise Linux Workstation (v. 7) · released 2021-12-02 · [advisory](https://access.redhat.com/errata/RHSA-2021:4913)\n- **RHSA-2021:5081** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v. 8.1) · released 2021-12-13 · [advisory](https://access.redhat.com/errata/RHSA-2021:5081)\n- **RHSA-2021:5080** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 8.2) · released 2021-12-13 · [advisory](https://access.redhat.com/errata/RHSA-2021:5080)\n- **RHSA-2021:4915** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.8.4) · released 2021-12-02 · [advisory](https://access.redhat.com/errata/RHSA-2021:4915)\n- **RHSA-2021:4916** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2021-12-02 · [advisory](https://access.redhat.com/errata/RHSA-2021:4916)\n- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 6 · no fix planned: Red Hat Enterprise Linux 6 · updated 2026-09-07 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-44227.json)\n\n**mailman: CSRF token bypass allows to perform CSRF attacks and admin takeover** — rated Important by Red Hat. Released 2021-11-26, updated 2026-09-07.\n\nAffected:\n\n- Red Hat Enterprise Linux 6\n\nFixed:\n\n- Red Hat Enterprise Linux Server (v. 7)\n- Red Hat Enterprise Linux Workstation (v. 7)\n- Red Hat Enterprise Linux AppStream E4S (v. 8.1)\n- Red Hat Enterprise Linux AppStream EUS (v. 8.2)\n- Red Hat Enterprise Linux AppStream EUS (v.8.4)\n- Red Hat Enterprise Linux AppStream (v. 8)\n\nNo fix planned:\n\n- Red Hat Enterprise Linux 6\n\n## Remediation\n\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2021:4913\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2021:5081\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2021:5080\n\nWorkarounds / mitigations:\n\n- Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.\n\n## Package advisory (CVE-2021-44227)\n\nAffected packages:\n\n- `mailman < 2.1.38`\n\nPatched in:\n\n- `mailman 2.1.38`\n\nSource: https://osv.dev/vulnerability/GHSA-xq58-69h2-765m","depth":"twilight","depthScore":44,"depthScoreParts":{"impact":44,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":4553,"id":"CVE-2021-44227","ts":1788887189802,"field":"cvss","old":"8.8","new":"8"},{"seq":3436,"id":"CVE-2021-44227","ts":1788886307039,"field":"cvss","old":"8","new":"8.8"},{"seq":3248,"id":"CVE-2021-44227","ts":1788883138094,"field":"cvss","old":"8.8","new":"8"}]}