[Mailman-Users] Re: Mailman 2.1 security release

2021-11-12 Thread Mark Sapiro
On 11/12/21 4:01 PM, Mark Sapiro wrote: Mailman 2.1.36 had a serious bug. Thanks to Joel Lord for finding and reporting it. I have just released Mailman 2.1.37 to fix that issue. It is reported at https://bugs.launchpad.net/mailman/+bug/1950833 and is fixed at

[Mailman-Users] Re: Mailman 2.1 security release

2021-11-12 Thread Mark Sapiro
Mailman 2.1.36 had a serious bug. Thanks to Joel Lord for finding and reporting it. I have just released Mailman 2.1.37 to fix that issue. It is reported at https://bugs.launchpad.net/mailman/+bug/1950833 and is fixed at https://bazaar.launchpad.net/~mailman-coders/mailman/2.1/revision/1878

[Mailman-Users] Mailman 2.1 security release

2021-11-12 Thread Mark Sapiro
I am pleased to announce the release of Mailman 2.1.36. This is a security release. It fixes https://bugs.launchpad.net/mailman/+bug/1949401 CVE-2021-43331 and https://bugs.launchpad.net/mailman/+bug/1949403 CVE-2021-43332. The former of these could allow an XSS attack against the user