VDB
DEBIAN-CVE-2019-5885
DEBIAN-CVE-2019-5885
REJECTED
CVSS 7.5 HIGH
Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable value to derive a secret key and other secrets which could allow remote attackers to impersonate users.
Risk Scores
CVSS v3.0
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:14 | matrix-synapse | 0, 0.19.2+dfsg, 0.19.2+dfsg |
Timeline
- Apr 19, 2026 CVE Rejected