matrix.org/content/blog/2018/08/2018-08-02-security-update-...

1.0 KiB

+++ title = "Security update: Synapse 0.33.1" path = "/blog/2018/08/02/security-update-synapse-0-33-1"

[taxonomies] author = ["Neil Johnson"] category = ["Releases", "Security"] +++

Hi All,

We have patched two securities vulnerabilities (details follow), we do not believe either have been exploited in the wild, but recommend upgrading asap.

As always you can get the new update from https://github.com/matrix-org/synapse/releases/tag/v0.33.1 or from any of the sources mentioned at https://github.com/matrix-org/synapse/

Thanks

Changes in Synapse v0.33.1 (2018-08-2)

  • Fix a potential issue where servers could request events for rooms they have not joined. (#3641)
  • Fix a potential issue where users could see events in private rooms before they joined. (#3642)