NA

CVE-2021-35057

Vulnerability Summary

A security issue has been found in HyperKitty before version 1.3.5, where the secret archiver key is vulnerable to timing attacks. This is only exploitable if you can send a request from a approved IP listed in MAILMAN_ARCHIVER_FROM.

Vendor Advisories

A security issue has been found in HyperKitty before version 135, where the secret archiver key is vulnerable to timing attacks This is only exploitable if you can send a request from a approved IP listed in MAILMAN_ARCHIVER_FROM ...