Description
Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable value to derive a secret key and other secrets which could allow remote attackers to impersonate users.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-0084 | Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable value to derive a secret key and other secrets which could allow remote attackers to impersonate users. |
Github GHSA |
GHSA-jrqm-v8cv-53ww | Matrix Synapse Predictable Secret Key |
Ubuntu USN |
USN-6076-1 | Synapse vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T20:09:23.762Z
Reserved: 2019-01-10T00:00:00.000Z
Link: CVE-2019-5885
No data.
Status : Modified
Published: 2019-03-21T16:01:05.843
Modified: 2024-11-21T04:45:42.433
Link: CVE-2019-5885
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA
Ubuntu USN