Timing Attack Vulnerability in Mailman Core by GNU
CVE-2021-34337
6.3MEDIUM
What is CVE-2021-34337?
A vulnerability exists in Mailman Core prior to version 3.3.5 that allows an attacker with access to the REST API to exploit timing discrepancies in API responses. By observing the time it takes for requests to process, an attacker can infer the configured REST API password. Although the REST API is bound to localhost by default—a measure that limits exposure—users can opt to allow it to listen on other interfaces, which amplifies the potential for exploitation. This makes it crucial for users to update their installations to guard against unauthorized API access.