Vulnerabilities > Matrix > Synapse > 1.20.0

DATE CVE VULNERABILITY TITLE RISK
2020-10-19 CVE-2020-26891 Cross-site Scripting vulnerability in Matrix Synapse
AuthRestServlet in Matrix Synapse before 1.21.0 is vulnerable to XSS due to unsafe interpolation of the session GET parameter.
network
matrix CWE-79
4.3