Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2021:0861-1

Опубликовано: 09 июн. 2021
Источник: suse-cvrf

Описание

Security update for python-HyperKitty

This update for python-HyperKitty fixes the following issues:

  • CVE-2021-33038 [boo#1186575], information disclosure when importing a private mailing list

Список пакетов

openSUSE Leap 15.2
python3-HyperKitty-1.3.2-lp152.2.3.1

Описание

An issue was discovered in management/commands/hyperkitty_import.py in HyperKitty through 1.3.4. When importing a private mailing list's archives, these archives are publicly visible for the duration of the import. For example, sensitive information might be available on the web for an hour during a large migration from Mailman 2 to Mailman 3.


Затронутые продукты
openSUSE Leap 15.2:python3-HyperKitty-1.3.2-lp152.2.3.1

Ссылки