FreeBSD : py-matrix-synapse -- users of single-sign-on are vulnerable to phishing (1afe9552-5ee3-11ea-9b6d-901b0e934d69)

high Nessus Plugin ID 134438

Language:

Synopsis

The remote FreeBSD host is missing one or more security-related updates.

Description

Matrix developers report :

[The 1.11.1] release includes a security fix impacting installations using Single Sign-On (i.e. SAML2 or CAS) for authentication.
Administrators of such installations are encouraged to upgrade as soon as possible.

Solution

Update the affected packages.

See Also

https://github.com/matrix-org/synapse/releases/tag/v1.11.1

http://www.nessus.org/u?a91f1458

Plugin Details

Severity: High

ID: 134438

File Name: freebsd_pkg_1afe95525ee311ea9b6d901b0e934d69.nasl

Version: 1.1

Type: local

Published: 3/12/2020

Updated: 3/12/2020

Supported Sensors: Nessus

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:py35-matrix-synapse, p-cpe:/a:freebsd:freebsd:py36-matrix-synapse, p-cpe:/a:freebsd:freebsd:py37-matrix-synapse, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 3/11/2020

Vulnerability Publication Date: 3/3/2020