It was discovered that Mailman incorrectly handled CSRF tokens. A remote list member or moderator could possibly use their own token to craft an admin request CSRF attack and set a new admin password or make other changes.
1:2.1.20-1ubuntu0.6+esm31:2.1.29-1ubuntu3.1+esm2