Go to file
Oliver Kurz c44471789a Accepting request 985625 from home:darix:apps
- Update to 1.61.1
  This patch release fixes a security issue regarding URL previews,
  affecting all prior versions of Synapse. Server administrators
  are encouraged to update Synapse as soon as possible. We are not
  aware of these vulnerabilities being exploited in the wild.
  Server administrators who are unable to update Synapse may use
  the workarounds described in the linked GitHub Security Advisory
  below.
  The following issue is fixed in 1.61.1.
  GHSA-22p3-qrh9-cx32 / CVE-2022-31052
  Synapse instances with the url_preview_enabled homeserver config
  option set to true are affected. URL previews of some web pages
  can lead to unbounded recursion, causing the request to either
  fail, or in some cases crash the running Synapse process.
  Requesting URL previews requires authentication. Nevertheless, it
  is possible to exploit this maliciously, either by malicious
  users on the homeserver, or by remote users sending URLs that a
  local user's client may automatically request a URL preview for.
  Homeservers with the url_preview_enabled configuration option set
  to false (the default) are unaffected. Instances with the
  enable_media_repo configuration option set to false are also
  unaffected, as this also disables URL preview functionality.
  Fixed by fa1308061802ac7b7d20e954ba7372c5ac292333.

- force python 3.10 on TW

OBS-URL: https://build.opensuse.org/request/show/985625
OBS-URL: https://build.opensuse.org/package/show/network:messaging:matrix/matrix-synapse?expand=0&rev=228
2022-06-28 16:33:36 +00:00
_service Accepting request 985625 from home:darix:apps 2022-06-28 16:33:36 +00:00
.gitattributes osc copypac from project:home:okurz:matrix-synapse package:matrix-synapse revision:14 2017-06-18 18:49:01 +00:00
.gitignore osc copypac from project:home:okurz:matrix-synapse package:matrix-synapse revision:14 2017-06-18 18:49:01 +00:00
10719-Fix-instert-of-duplicate-key-into-event_json.patch Accepting request 915742 from openSUSE:infrastructure:matrix 2021-09-21 11:12:57 +00:00
bump-dependencies.patch Accepting request 974666 from home:darix:apps 2022-05-03 14:42:43 +00:00
matrix-synapse-1.4.1-paths.patch Accepting request 974666 from home:darix:apps 2022-05-03 14:42:43 +00:00
matrix-synapse-1.61.1.obscpio Accepting request 985625 from home:darix:apps 2022-06-28 16:33:36 +00:00
matrix-synapse-generate-config.sh Accepting request 768057 from home:darix:apps 2020-02-03 10:56:06 +00:00
matrix-synapse-test.spec Accepting request 985625 from home:darix:apps 2022-06-28 16:33:36 +00:00
matrix-synapse-user.conf Accepting request 897230 from home:darix:apps 2021-06-04 18:07:57 +00:00
matrix-synapse.changes Accepting request 985625 from home:darix:apps 2022-06-28 16:33:36 +00:00
matrix-synapse.obsinfo Accepting request 985625 from home:darix:apps 2022-06-28 16:33:36 +00:00
matrix-synapse.service Accepting request 768057 from home:darix:apps 2020-02-03 10:56:06 +00:00
matrix-synapse.spec Accepting request 985625 from home:darix:apps 2022-06-28 16:33:36 +00:00
matrix-synapse.tmpfiles.d Accepting request 768057 from home:darix:apps 2020-02-03 10:56:06 +00:00
README.SUSE Accepting request 768057 from home:darix:apps 2020-02-03 10:56:06 +00:00
series Accepting request 974666 from home:darix:apps 2022-05-03 14:42:43 +00:00

 README.SUSE
-------------

 Bootstrapping a server
========================

/usr/sbin/matrix-synapse-generate-config servername