CVE-2019-5885

Severity CVSS v4.0:
Pending analysis
Type:
CWE-330 Use of Insufficiently Random Value
Publication date:
21/03/2019
Last modified:
07/11/2023

Description

Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable value to derive a secret key and other secrets which could allow remote attackers to impersonate users.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:matrix:synapse:*:*:*:*:*:*:*:* 0.34.0.1 (excluding)
cpe:2.3:o:fedoraproject:fedora:28:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*