diff --git a/security/vuxml/vuln-2021.xml b/security/vuxml/vuln-2021.xml index 2b7395808059..31ce37c2583d 100644 --- a/security/vuxml/vuln-2021.xml +++ b/security/vuxml/vuln-2021.xml @@ -1,3 +1,42 @@ + + py-matrix-synapse -- several vulnerabilities + + + py36-matrix-synapse + py37-matrix-synapse + py38-matrix-synapse + py39-matrix-synapse + py310-matrix-synapse + 1.41.1 + + + + +

Matrix developers report:

+
+

This release patches two moderate severity issues which + could reveal metadata about private rooms:

+
    +
  • CVE-2021-39164: Enumerating a private room's list of + members and their display names.
  • +
  • CVE-2021-39163: Disclosing a private room's name, + avatar, topic, and number of members.
  • +
+
+ +
+ + ports/258187 + CVE-2021-39164 + CVE-2021-39163 + https://matrix.org/blog/2021/08/31/synapse-1-41-1-released + + + 2021-08-31 + 2021-09-02 + +
+ Python -- multiple vulnerabilities