CVE-2019-5885: High severity matrix synapse vulnerability
Matrix Synapse before 0.34.0.1, when the macaroonsecretkey authentication parameter is not set, uses a predictable value to derive a secret key and other secrets which could allow remote attackers to impersonate users.
Other sources
Matrix Synapse before 0.34.0.1, when the macaroonsecretkey authentication parameter is not set, uses a predictable value to derive a secret key and other secrets which could allow remote attackers to impersonate users.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-5885?
CVE-2019-5885 is a vulnerability found in Matrix Synapse before version 0.34.0.1 that allows remote attackers to impersonate users.
How severe is CVE-2019-5885?
CVE-2019-5885 has a severity rating of 7.5 (High).
Which software is affected by CVE-2019-5885?
Matrix Synapse before version 0.34.0.1 and certain versions of Fedora (28 and 29) are affected by CVE-2019-5885.
How can remote attackers exploit CVE-2019-5885?
Remote attackers can exploit CVE-2019-5885 by impersonating users due to the predictable value used to derive secret keys and other secrets.
Are there any remedies for CVE-2019-5885?
Yes, upgrading to version 0.34.0.1 of Matrix Synapse fixes the vulnerability.