FS#70801 - [matrix-synapse] [Security] denial of service (CVE-2021-29471, GHSA-7h5v-85w9-pq6c)
            Attached to Project:
            Community Packages
            
Opened by Jonas Witschel (diabonas) - Tuesday, 11 May 2021, 15:57 GMT
Last edited by Jonas Witschel (diabonas) - Tuesday, 11 May 2021, 18:17 GMT
          Opened by Jonas Witschel (diabonas) - Tuesday, 11 May 2021, 15:57 GMT
Last edited by Jonas Witschel (diabonas) - Tuesday, 11 May 2021, 18:17 GMT
                
  | 
              
                Details
                    Summary 
                ======= The package matrix-synapse is vulnerable to denial of service via CVE-2021-29471 and GHSA-7h5v-85w9-pq6c. Guidance ======== Upgrading matrix-synapse to the latest version 1.33.2 (https://github.com/matrix-org/synapse/releases/tag/v1.33.2) fixes these issues. References ========== https://security.archlinux.org/AVG-1943 https://github.com/matrix-org/synapse/security/advisories/GHSA-x345-32rc-8h85 https://github.com/matrix-org/synapse/commit/03318a766cac9f8b053db2214d9c332a977d226c https://github.com/matrix-org/synapse/security/advisories/GHSA-7h5v-85w9-pq6c https://github.com/matrix-org/synapse/pull/9855 https://github.com/matrix-org/synapse/commit/177dae270420ee4b4c8fa5e2c74c5081d98da320  | 
            
              This task depends upon
              
              
            
            
          
            Closed by  Jonas Witschel (diabonas)
Tuesday, 11 May 2021, 18:17 GMT
Reason for closing: Fixed
Additional comments about closing: matrix-synapse 1.33.2-1 in [community-testing]
          
        Tuesday, 11 May 2021, 18:17 GMT
Reason for closing: Fixed
Additional comments about closing: matrix-synapse 1.33.2-1 in [community-testing]