CVE-2021-33038
Summary
| CVE | CVE-2021-33038 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-05-26 14:15:00 UTC |
| Updated | 2022-06-28 14:11:00 UTC |
| Description | An issue was discovered in management/commands/hyperkitty_import.py in HyperKitty through 1.3.4. When importing a private mailing list's archives, these archives are publicly visible for the duration of the import. For example, sensitive information might be available on the web for an hour during a large migration from Mailman 2 to Mailman 3. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Discovering and fixing CVE-2021-33038 in Mailman3 – [[WM:TECHBLOG]] |
MISC |
techblog.wikimedia.org |
|
| Debian -- Security Information -- DSA-4922-1 hyperkitty |
DEBIAN |
www.debian.org |
|
| Ensure private archives stay private during import (CVE-2021-33038) (90253245) · Commits · GNU Mailman / HyperKitty · GitLab |
CONFIRM |
gitlab.com |
|
| hyperkitty_import command leaves archives public until import finishes (#380) · Issues · GNU Mailman / HyperKitty · GitLab |
CONFIRM |
gitlab.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 178621 Debian Security Update for hyperkitty (DSA 4922-1)
- 178636 Debian Security Update for hyperkitty (DSA 4922-1)
- 179661 Debian Security Update for hyperkitty (CVE-2021-33038)
- 750165 OpenSUSE Security Update for python-HyperKitty (openSUSE-SU-2021:0861-1)
- 982085 Python (pip) Security Update for HyperKitty (GHSA-h39g-q63v-4h9p)