Debian Hyperkitty vulnerabilities
2 known vulnerabilities affecting debian/hyperkitty.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1LOW1
Vulnerabilities
Page 1 of 1
CVE-2021-33038HIGHCVSS 7.5fixed in hyperkitty 1.3.4-4 (bookworm)2021
CVE-2021-33038 [HIGH] CVE-2021-33038: hyperkitty - An issue was discovered in management/commands/hyperkitty_import.py in HyperKitt...
An issue was discovered in management/commands/hyperkitty_import.py in HyperKitty through 1.3.4. When importing a private mailing list's archives, these archives are publicly visible for the duration of the import. For example, sensitive information might be available on the web for an hour during a large migration from Mailman 2 to Mailman 3.
Scope: local
bookwo
debian
CVE-2021-25322LOWCVSS 6.82021
CVE-2021-25322 [MEDIUM] CVE-2021-25322: hyperkitty - A UNIX Symbolic Link (Symlink) Following vulnerability in python-HyperKitty of o...
A UNIX Symbolic Link (Symlink) Following vulnerability in python-HyperKitty of openSUSE Leap 15.2, Factory allows local attackers to escalate privileges from the user hyperkitty or hyperkitty-admin to root. This issue affects: openSUSE Leap 15.2 python-HyperKitty version 1.3.2-lp152.2.3.1 and prior versions. openSUSE Factory python-HyperKitty versions prior to
debian