Hey everyone, it's time for a new Synapse release! Synapse
1.69 is out, fresh
out of the oven. But before we take a look at it, here's a quick announcement:
We have recently disclosed a moderate severity security vulnerability, which
was fixed in Synapse
1.62 (released on
July 5th 2022). This issue affects all homeservers running a version of
Synapse older than 1.62 with open federation. If this is the case for your
deployment, please update to a more recent version of Synapse at your earliest
convenience.
See advisory
GHSA-jhjh-776m-4765
and CVE-2022-31152 for more
information.
Now let's see what's new in Synapse 1.69!
Continue reading…
Hey all,
It’s finally here: threads, edits, and private read receipts. v1.4 has been a little later than usual in the quarter because we wanted to make sure we nailed down all the core MSCs for threads before publishing the spec itself, but we’ve done that now and we’re excited about it.
Continue reading…
We will be releasing a security update to matrix-js-sdk, matrix-ios-sdk and matrix-android-sdk2 and clients which implement end-to-end encryption with these libraries, to patch critical security issues, on Wed, Sept 28th. The releases will be published in the afternoon, followed by the disclosure blog post around 16:00 UTC. The affected clients include Element Web, Desktop, iOS and Android. We will also be working with downstream packagers and forks over the coming days to ensure a synchronised release to address affected clients.
Clients using matrix-rust-sdk, hydrogen-sdk and matrix-nio are not affected by these critical issues. We are also auditing third-party client SDKs and clients in advance of the release, and will work with the projects if action is needed. So far we've confirmed that other popular SDK/clients including mtxclient (nheko), Matrix Dart SDK (FluffyChat), Trixnity (Timmy), Syphon, mautrix-go (Gomuks) and mautrix-python are not affected by the issues in question.
If you maintain or package a (potentially) affected E2EE-capable Matrix client and need to coordinate on the release, please contact security@matrix.org.
We advise to upgrade as soon as possible after the patched versions are released.
Thank you for your patience while we work to resolve this issue.