High severity7.5NVD Advisory· Published May 26, 2021· Updated Jun 17, 2026
CVE-2021-33038
CVE-2021-33038
Description
An issue was discovered in management/commands/hyperkitty_import.py in HyperKitty through 1.3.4. When importing a private mailing list's archives, these archives are publicly visible for the duration of the import. For example, sensitive information might be available on the web for an hour during a large migration from Mailman 2 to Mailman 3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
HyperKittyPyPI | < 1.3.5 | 1.3.5 |
Affected products
5- HyperKitty/HyperKittydescription
- ghsa-coords2 versions
< 1.3.5+ 1 more
- (no CPE)range: < 1.3.5
- (no CPE)range: < 1.3.2-lp152.2.3.1
Patches
Vulnerability mechanics
References
9- gitlab.com/mailman/hyperkitty/-/commit/9025324597d60b2dff740e49b70b15589d6804fanvdPatchThird Party AdvisoryWEB
- techblog.wikimedia.org/2021/06/11/discovering-and-fixing-cve-2021-33038-in-mailman3/nvdPatchThird Party Advisory
- gitlab.com/mailman/hyperkitty/-/issues/380nvdExploitIssue TrackingPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-h39g-q63v-4h9pghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-33038ghsaADVISORY
- www.debian.org/security/2021/dsa-4922nvdThird Party AdvisoryWEB
- github.com/pypa/advisory-database/tree/main/vulns/hyperkitty/PYSEC-2021-77.yamlghsaWEB
- gitlab.com/mailman/hyperkitty/-/blob/master/doc/news.rstghsaWEB
- techblog.wikimedia.org/2021/06/11/discovering-and-fixing-cve-2021-33038-in-mailman3ghsaWEB
News mentions
0No linked articles in our index yet.