Package: hyperkitty / 1.2.2-1+deb10u1
Metadata
| Package | Version | Patches format |
|---|---|---|
| hyperkitty | 1.2.2-1+deb10u1 | 3.0 (quilt) |
Patch series
view the series file| Patch | File delta | Description |
|---|---|---|
| 0001_README_remove_embedded_images.patch | (download) |
README.rst |
15 0 + 15 - 0 ! |
_readme_remove_embedded_images |
| 0002 Ensure private archives stay private during import C.patch | (download) |
hyperkitty/management/commands/hyperkitty_import.py |
7 6 + 1 - 0 ! |
ensure private archives stay private during import (cve-2021-33038) hyperkitty keeps state of whether a mailing list's archives should be public or private in the hyperkitty_mailinglist table. However during the import process, it would create a row using the default settings (archive_policy="public") instead of getting the correct values from Mailman. It would only sync with Mailman at the end of the import process. This patch explicitly creates the hyperkitty_mailinglist row/object at the beginning of the import process, so the visiblity will be correctly obtained from Mailman, before any messages can be accidentally leaked. |
1
