Debian Linux Security Advisory 4970-1 - Kevin Israel discovered that Postorius, the administrative web frontend for Mailman 3, didn't validate whether a logged-in user owns the email address when unsubscribing.
d0c0d8c9e3c781e6faf36980659196a409ce5700fd69a57831a82485c7e65a85