Synapse v1.21.2 Release Notes
Release Date: 2020-10-15 // over 3 years ago-
Synapse 1.21.2 (2020-10-15)
๐ Debian packages and Docker images have been rebuilt using the latest versions of dependency libraries, including authlib 0.15.1. Please see bugfixes below.
๐ Security advisory
โฌ๏ธ HTML pages served via Synapse were vulnerable to cross-site scripting (XSS) attacks. All server administrators are encouraged to upgrade. (#8444) (CVE-2020-26891)
๐ This fix was originally included in v1.21.0 but was missing a security advisory.
This was reported by Denis Kasak.
๐ Bugfixes