Matomo 0.2.33, response to CVE-2009-1085

Contents

Ready to use in minutes, Matomo gives you:
✔ Accurate privacy-first analytics
✔ Full data ownership
✔ GDPR compliance

Reference: CVE-2009-1085 dated 03/25/2009

Contrary to the advisory, the Matomo (Piwik) project did not “confirm” this “vulnerability”. We have classified this issue as user error. The subject file, “misc/cron/archive.sh”, was intended to be a sample shell script. By default, archiving is an internal Matomo process, and an external “archive.sh” file is not required nor used in most installations. Users who required the cron-based archiving were expected to copy the file to a secure location and configure it to their environment, since the sample file is always overwritten by the software update process.

The only way to expose the API key in “archive.sh” would be for a user to manually edit this file in-situ. Matomo does not “store” the API key in “archive.sh” as alleged in the advisory — not through the installer, not through the admin panel. Matomo never configures this file with the superuser’s API key. To reiterate, Matomo never modifies this file.

Starting with Matomo version 0.2.33 (released Apr 7, 2009), “archive.sh” is production-ready and will programmatically fetch the API key from the user’s (private) configuration file.

Matomo users who have configured “archive.sh” (up to and including Matomo version 0.2.32) are advised to update to the latest version of Matomo, or restrict access to this script by either “.htaccess” or moving the script outside the web document root.

Get started with Matomo

By choosing Matomo, the ethical analytics alternative, you won’t make privacy sacrifices or compromise your site.

Enjoyed this post?
Join the 160,000+ subscribers who receive the Matomo Newsletter straight to their inbox every month

Subscribe to our newsletter to receive regular information about Matomo. You can unsubscribe at any time from it. This service uses SendGrid. Learn more about it within our privacy Policy page.

Certified ISO 27001:2022

Your analytics data is protected by globally recognised security standards. ISO 27001 certification means we follow the highest international standards for information security management.

Live websites using Matomo worldwide
0 K
Websites using Matomo including historical
0 M
Customer satisfaction
0 %

Own your data. Protect your privacy. Unlock better analytics.

Organisations should be able to understand their digital performance while mainteaning full ownership and control of their data.

No credit card required.