CVE-2019-5885 PUBLISHED

Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable value to derive a secret key and other secrets which could allow remote attackers to impersonate users.

EPSS 0.78% · 73.6th percentile

Risk Scores

EPSS Score
0.78%
73.6th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:18.04:LTSmatrix-synapse0, 0.19.2+dfsg-6, 0.24.0+dfsg-1

Timeline

References

Open in Interactive Console →