Red Hat Bugzilla – Bug 1370155
CVE-2016-6893 mailman: CSRF protection missing in the user options page
Last modified: 2016-08-29 00:42:30 EDT
A CSRF vulnerability was found in mailman's user options page. This could conceivably allow an attacker to obtain a user's password. References: https://mail.python.org/pipermail/mailman-announce/2016-August/000225.html
Created mailman tracking bugs for this issue: Affects: fedora-all [bug 1370156]
Upstream patch: https://mail.python.org/pipermail/mailman-announce/2016-August/000226.html