ArchLinux: 202011-4: matrix-synapse: cross-site scripting
Summary
A security issue has been found in matrix-synapse before 1.21.0, where HTML pages served via Synapse were vulnerable to cross-site scripting (XSS) attacks.
Resolution
Upgrade to 1.21.0-1.
# pacman -Syu "matrix-synapse>=1.21.0-1"
The problem has been fixed upstream in version 1.21.0.
References
https://github.com/matrix-org/synapse/releases/tag/v1.21.2 https://github.com/matrix-org/synapse/pull/8444 https://security.archlinux.org/CVE-2020-26891
Workaround
None.