Описание
Security update for python-HyperKitty
This update for python-HyperKitty fixes the following issues:
- CVE-2021-33038 [boo#1186575], information disclosure when importing a private mailing list
Список пакетов
openSUSE Leap 15.2
python3-HyperKitty-1.3.2-lp152.2.3.1
Ссылки
- E-Mail link for openSUSE-SU-2021:0861-1
- SUSE Security Ratings
- SUSE Bug 1186575
- SUSE CVE CVE-2021-33038 page
Описание
An issue was discovered in management/commands/hyperkitty_import.py in HyperKitty through 1.3.4. When importing a private mailing list's archives, these archives are publicly visible for the duration of the import. For example, sensitive information might be available on the web for an hour during a large migration from Mailman 2 to Mailman 3.
Затронутые продукты
openSUSE Leap 15.2:python3-HyperKitty-1.3.2-lp152.2.3.1
Ссылки
- CVE-2021-33038
- SUSE Bug 1186575