FS#70801 - [matrix-synapse] [Security] denial of service (CVE-2021-29471, GHSA-7h5v-85w9-pq6c)
Attached to Project:
Community Packages
Opened by Jonas Witschel (diabonas) - Tuesday, 11 May 2021, 15:57 GMT
Last edited by Jonas Witschel (diabonas) - Tuesday, 11 May 2021, 18:17 GMT
Opened by Jonas Witschel (diabonas) - Tuesday, 11 May 2021, 15:57 GMT
Last edited by Jonas Witschel (diabonas) - Tuesday, 11 May 2021, 18:17 GMT
|
Details
Summary
======= The package matrix-synapse is vulnerable to denial of service via CVE-2021-29471 and GHSA-7h5v-85w9-pq6c. Guidance ======== Upgrading matrix-synapse to the latest version 1.33.2 (https://github.com/matrix-org/synapse/releases/tag/v1.33.2) fixes these issues. References ========== https://security.archlinux.org/AVG-1943 https://github.com/matrix-org/synapse/security/advisories/GHSA-x345-32rc-8h85 https://github.com/matrix-org/synapse/commit/03318a766cac9f8b053db2214d9c332a977d226c https://github.com/matrix-org/synapse/security/advisories/GHSA-7h5v-85w9-pq6c https://github.com/matrix-org/synapse/pull/9855 https://github.com/matrix-org/synapse/commit/177dae270420ee4b4c8fa5e2c74c5081d98da320 |
This task depends upon
Closed by Jonas Witschel (diabonas)
Tuesday, 11 May 2021, 18:17 GMT
Reason for closing: Fixed
Additional comments about closing: matrix-synapse 1.33.2-1 in [community-testing]
Tuesday, 11 May 2021, 18:17 GMT
Reason for closing: Fixed
Additional comments about closing: matrix-synapse 1.33.2-1 in [community-testing]