An issue was discovered in management/commands/hyperkitty_import.py in HyperKitty through 1.3.4. When importing a private mailing list's archives, these archives are publicly visible for the duration of the import. For example, sensitive information might be available on the web for an hour during a large migration from Mailman 2 to Mailman 3.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-4922-1 | hyperkitty security update |
EUVD |
EUVD-2021-0099 | An issue was discovered in management/commands/hyperkitty_import.py in HyperKitty through 1.3.4. When importing a private mailing list's archives, these archives are publicly visible for the duration of the import. For example, sensitive information might be available on the web for an hour during a large migration from Mailman 2 to Mailman 3. |
Github GHSA |
GHSA-h39g-q63v-4h9p | Exposure of sensitive information to an unauthorized actor in HyperKitty |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T23:42:19.473Z
Reserved: 2021-05-17T00:00:00
Link: CVE-2021-33038
No data.
Status : Modified
Published: 2021-05-26T14:15:08.913
Modified: 2024-11-21T06:08:10.530
Link: CVE-2021-33038
No data.
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Github GHSA