View | Details | Raw Unified | Return to bug 247720 | Differences between
and this patch

Collapse All | Expand All

(-)security/vuxml/vuln.xml (+31 lines)
Lines 58-63 Link Here
58
  * Do not forget port variants (linux-f10-libxml2, libxml2, etc.)
58
  * Do not forget port variants (linux-f10-libxml2, libxml2, etc.)
59
-->
59
-->
60
<vuxml xmlns="http://www.vuxml.org/apps/vuxml-1">
60
<vuxml xmlns="http://www.vuxml.org/apps/vuxml-1">
61
  <vuln vid="2f61c757-bc81-11ea-88cc-901b0e934d69">
62
    <topic>py-matrix-synapse -- multiple vulnerabilities</topic>
63
    <affects>
64
      <package>
65
	<name>py36-matrix-synapse</name>
66
	<name>py37-matrix-synapse</name>
67
	<name>py38-matrix-synapse</name>
68
	<range><lt>1.15.2</lt></range>
69
      </package>
70
    </affects>
71
    <description>
72
      <body xmlns="http://www.w3.org/1999/xhtml">
73
	<p>Matrix developers report:</p>
74
	<blockquote cite="https://github.com/matrix-org/synapse/releases/tag/v1.15.2">
75
	  <p>Due to the two security issues highlighted below, server administrators are encouraged to update Synapse. We are not aware of these vulnerabilities being exploited in the wild.</p>
76
	  <ul>
77
	    <li>A malicious homeserver could force Synapse to reset the state in a room to a small subset of the correct state. This affects all Synapse deployments which federate with untrusted servers.</li>
78
	    <li>HTML pages served via Synapse were vulnerable to clickjacking attacks. This predominantly affects homeservers with single-sign-on enabled, but all server administrators are encouraged to upgrade.</li>
79
	  </ul>
80
	</blockquote>
81
      </body>
82
    </description>
83
    <references>
84
      <url>https://github.com/matrix-org/synapse/releases/tag/v1.15.2</url>
85
    </references>
86
    <dates>
87
      <discovery>2020-07-02</discovery>
88
      <entry>2020-07-02</entry>
89
    </dates>
90
  </vuln>
91
61
  <vuln vid="0a305431-bc98-11ea-a051-001b217b3468">
92
  <vuln vid="0a305431-bc98-11ea-a051-001b217b3468">
62
    <topic>Gitlab -- Multiple Vulnerabilities</topic>
93
    <topic>Gitlab -- Multiple Vulnerabilities</topic>
63
    <affects>
94
    <affects>

Return to bug 247720