automation: Update matrix-synapse Docker tag to v1.86.0
This MR contains the following updates:
Package | Update | Change |
---|---|---|
matrix-synapse | minor |
1.84.1 -> 1.86.0
|
Release Notes
matrix-org/synapse
v1.86.0
===========================
No significant changes since 1.86.0rc2.
v1.85.2
===========================
Bugfixes
- Fix regression where using TLS for HTTP replication between workers did not work. Introduced in v1.85.0. (#15746)
v1.85.1
===========================
Note: this release only fixes a bug that stopped some deployments from upgrading to v1.85.0. There is no need to upgrade to v1.85.1 if successfully running v1.85.0.
Bugfixes
- Fix bug in schema delta that broke upgrades for some deployments. Introduced in v1.85.0. (#15738, #15739)
v1.85.0
===========================
No significant changes since 1.85.0rc2.
Security advisory
The following issues are fixed in 1.85.0 (and RCs).
-
GHSA-26c5-ppr8-f33p / CVE-2023-32682 — Low Severity
It may be possible for a deactivated user to login when using uncommon configurations.
-
GHSA-98px-6486-j7qc / CVE-2023-32683 — Low Severity
A discovered oEmbed or image URL can bypass the
url_preview_url_blacklist
setting potentially allowing server side request forgery or bypassing network policies. Impact is limited to IP addresses allowed by theurl_preview_ip_range_blacklist
setting (by default this only allows public IPs).
See the advisories for more details. If you have any questions, email security@matrix.org.
Configuration
-
If you want to rebase/retry this MR, check this box
This MR has been generated by Renovate Bot.