An issue was discovered in management/commands/hyperkitty_import.py in HyperKitty through 1.3.4. When importing a private mailing lists archives, these archives are publicly visible for the duration of the import. For example, sensitive information might be available on the web for an hour during a large migration from Mailman 2 to Mailman 3.
During installation, installed file permissions are set to allow anyone to modify those files.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Hyperkitty | Hyperkitty_project | * | 1.3.4 (including) |
Hyperkitty | Ubuntu | bionic | * |
Hyperkitty | Ubuntu | groovy | * |
Hyperkitty | Ubuntu | hirsute | * |
Hyperkitty | Ubuntu | impish | * |
Hyperkitty | Ubuntu | kinetic | * |
Hyperkitty | Ubuntu | lunar | * |
Hyperkitty | Ubuntu | mantic | * |
Hyperkitty | Ubuntu | trusty | * |
Hyperkitty | Ubuntu | xenial | * |