Matomo 1.1 – Security Advisory

Contents

Ready to use in minutes, Matomo gives you:
✔ Accurate privacy-first analytics
✔ Full data ownership
✔ GDPR compliance

Multiple XSS vulnerabilties are fixed by the Matomo (Piwik) 1.1 release.

Description:

CVE-2011-004. Matomo versions prior to 1.1 are vulnerable to multiple XSS vulnerabilities, both persistent and reflected.

This security update is rated critical, and Matomo users are strongly encouraged to update to the latest version of Matomo.

The Matomo project and community thanks Stefan Esser of SektionEins for leading the software security audit. The Matomo project also appreciates the coordinated disclosures from Jarosław Sajko of Pentesters.pl, and Matomo contributor, Fabian Becker.

Update (January 12, 2011):
NIST has assigned additional CVEs for improvements made in this release:

  • CVE-2011-398 – Potential spoofing of the X-Forwarded-For header. As of Matomo 1.1, users must configure the proxy header(s) to be trusted. (credit: Stefan Esser)
  • CVE-2011-399 – Login forms may be framed. As of Matomo 1.1, clickjacking countermeasures are activated by default. (The behaviour is configureable.) (credit: Anthon Pang)
  • CVE-2011-400 – Cookie.php does not set login cookie’s secure flag for https login. (credit: Anthon Pang)
  • CVE-2011-401 – Potential denial-of-service due to undeleted session files. This has been classified as a web server configuration error (e.g., default Debian configuration). Matomo mitigates by setting session.gc_probability, if unset.

Get started with Matomo

By choosing Matomo, the ethical analytics alternative, you won’t make privacy sacrifices or compromise your site.

Enjoyed this post?
Join the 160,000+ subscribers who receive the Matomo Newsletter straight to their inbox every month

Subscribe to our newsletter to receive regular information about Matomo. You can unsubscribe at any time from it. This service uses SendGrid. Learn more about it within our privacy Policy page.

Certifié ISO 27001:2022

Vos données analytics sont protégées par des standards de sécurité reconnus à l’international. La certification ISO 27001 garantit que nous appliquons les plus hauts standards de gestion de la sécurité de l’information.

Sites web en ligne à travers le monde
0 K
de sites web ont utilisé Matomo
0 M
de satisfaction client
0 %

Gardez le contrôle de vos données. Respectez la vie privée de vos utilisateurs. Accédez à des analyses plus performantes.

Les organisations devraient pouvoir comprendre leurs performances numériques tout en conservant la pleine propriété et le contrôle de leurs données.

Aucune carte bancaire requise.