Junglewise Threat Intelligence

CVE-2021-34337: PYSEC-2023-22 - An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the valu

CVE-2021-34337 · Severity: low · CVSS 3.1 · Published 2023-04-15

Technologies: mailman (PyPI). Vendors: PyPI.

Executive brief

Mailman Core is a widely-used mailing list management system. An attacker with access to the REST API could use timing attacks to guess the configured REST API password, then make unauthorized API calls to manage mailing lists and user subscriptions. By default the API only listens on localhost, limiting exposure, but administrators can optionally expose it on other network interfaces.

Technical details

The vulnerability is a timing attack (CWE-208) in Mailman Core's REST API password validation logic. An attacker with network access to the REST API endpoint can observe response time differences during password guessing attempts, allowing them to leak the password one character at a time. The REST API is bound to localhost by default, requiring an attacker to already have local system access or for the administrator to have configured the API to listen on other network interfaces. Once the password is compromised, an attacker can make arbitrary REST API calls to create/remove mailing lists, manage subscriptions, and access sensitive configuration. The vulnerability affects all versions before 3.3.5, which was patched to use constant-time password comparison.

Affected products

  • Mailman Mailman Core before 3.3.5

Timeline

  • 2023-04-15: disclosed
  • 2023-04-15: patched: version 3.3.5 released with fix

References

Related threats