Matomo 0.5, response to « Shocking News in PHP Exploitation »

Contents

Ready to use in minutes, Matomo gives you:
✔ Accurate privacy-first analytics
✔ Full data ownership
✔ GDPR compliance

The Matomo (Piwik) project acknowledges its exposure to the cookie exploit vulnerability described in Stefan Esser’s presentation, « Shocking News in PHP Exploitation« .

The potential security vulnerability exists in all versions of Matomo prior to version 0.5. While no exploit code has been posted, this is a serious threat given Matomo’s increasing popularity. As such, we strongly encourage all Matomo users to upgrade as soon as possible to the latest version of Matomo.

If you are unable to update to Matomo 0.5 or later, a small patch (released Dec. 8, 2009) to « core/Cookie.php » is available here.

Updated Dec 10, 2009: Candidate CVE identifier assigned: CVE-2009-4137
Updated Jan 14, 2011: Related CVE identifier: CVE-2009-4417

Get started with Matomo

By choosing Matomo, the ethical analytics alternative, you won’t make privacy sacrifices or compromise your site.

Enjoyed this post?
Join the 160,000+ subscribers who receive the Matomo Newsletter straight to their inbox every month

Subscribe to our newsletter to receive regular information about Matomo. You can unsubscribe at any time from it. This service uses SendGrid. Learn more about it within our privacy Policy page.

Certifié ISO 27001:2022

Vos données analytics sont protégées par des standards de sécurité reconnus à l’international. La certification ISO 27001 garantit que nous appliquons les plus hauts standards de gestion de la sécurité de l’information.

Sites web en ligne à travers le monde
0 K
de sites web ont utilisé Matomo
0 M
de satisfaction client
0 %

Gardez le contrôle de vos données. Respectez la vie privée de vos utilisateurs. Accédez à des analyses plus performantes.

Les organisations devraient pouvoir comprendre leurs performances numériques tout en conservant la pleine propriété et le contrôle de leurs données.

Aucune carte bancaire requise.