Go to file
Marcus Rueckert fdd3a7f61a Accepting request 933284 from home:darix:apps
- Update to 1.47.1
  This release fixes a security issue in the media store, affecting
  all prior releases of Synapse. Server administrators are
  encouraged to update Synapse as soon as possible. We are not
  aware of these vulnerabilities being exploited in the wild.
  Server administrators who are unable to update Synapse may use
  the workarounds described in the linked GitHub Security Advisory
  below.
  - Security Advisory:
    GHSA-3hfw-x7gx-437c / CVE-2021-41281: Path traversal when
    downloading remote media.
    Synapse instances with the media repository enabled can be
    tricked into downloading a file from a remote server into an
    arbitrary directory, potentially outside the media store
    directory.  The last two directories and file name of the path
    are chosen randomly by Synapse and cannot be controlled by an
    attacker, which limits the impact.  Homeservers with the media
    repository disabled are unaffected. Homeservers configured with
    a federation whitelist are also unaffected.  Fixed by
    91f2bd090.

OBS-URL: https://build.opensuse.org/request/show/933284
OBS-URL: https://build.opensuse.org/package/show/network:messaging:matrix/matrix-synapse?expand=0&rev=198
2021-11-23 14:50:11 +00:00
_service Accepting request 933284 from home:darix:apps 2021-11-23 14:50:11 +00:00
.gitattributes osc copypac from project:home:okurz:matrix-synapse package:matrix-synapse revision:14 2017-06-18 18:49:01 +00:00
.gitignore osc copypac from project:home:okurz:matrix-synapse package:matrix-synapse revision:14 2017-06-18 18:49:01 +00:00
10719-Fix-instert-of-duplicate-key-into-event_json.patch Accepting request 915742 from openSUSE:infrastructure:matrix 2021-09-21 11:12:57 +00:00
dont-bump-cryptography-with-system-openssl.patch Accepting request 903055 from home:darix:apps 2021-06-29 12:02:35 +00:00
matrix-synapse-1.4.1-paths.patch Accepting request 903055 from home:darix:apps 2021-06-29 12:02:35 +00:00
matrix-synapse-1.47.1.obscpio Accepting request 933284 from home:darix:apps 2021-11-23 14:50:11 +00:00
matrix-synapse-generate-config.sh Accepting request 768057 from home:darix:apps 2020-02-03 10:56:06 +00:00
matrix-synapse-test.spec Accepting request 933284 from home:darix:apps 2021-11-23 14:50:11 +00:00
matrix-synapse-user.conf Accepting request 897230 from home:darix:apps 2021-06-04 18:07:57 +00:00
matrix-synapse.changes Accepting request 933284 from home:darix:apps 2021-11-23 14:50:11 +00:00
matrix-synapse.obsinfo Accepting request 933284 from home:darix:apps 2021-11-23 14:50:11 +00:00
matrix-synapse.service Accepting request 768057 from home:darix:apps 2020-02-03 10:56:06 +00:00
matrix-synapse.spec Accepting request 933284 from home:darix:apps 2021-11-23 14:50:11 +00:00
matrix-synapse.tmpfiles.d Accepting request 768057 from home:darix:apps 2020-02-03 10:56:06 +00:00
README.SUSE Accepting request 768057 from home:darix:apps 2020-02-03 10:56:06 +00:00
series Accepting request 891065 from home:darix:apps 2021-05-10 17:56:48 +00:00

 README.SUSE
-------------

 Bootstrapping a server
========================

/usr/sbin/matrix-synapse-generate-config servername