First published: Tue Mar 19 2019(Updated: )
Matrix Synapse before 0.34.0.1, when the `macaroon_secret_key` authentication parameter is not set, uses a predictable value to derive a secret key and other secrets which could allow remote attackers to impersonate users.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Matrix Synapse | <0.34.0.1 | |
Fedoraproject Fedora | =28 | |
Fedoraproject Fedora | =29 | |
pip/matrix-synapse | <0.34.0.1 | 0.34.0.1 |
<0.34.0.1 | ||
=28 | ||
=29 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-5885 is a vulnerability found in Matrix Synapse before version 0.34.0.1 that allows remote attackers to impersonate users.
CVE-2019-5885 has a severity rating of 7.5 (High).
Matrix Synapse before version 0.34.0.1 and certain versions of Fedora (28 and 29) are affected by CVE-2019-5885.
Remote attackers can exploit CVE-2019-5885 by impersonating users due to the predictable value used to derive secret keys and other secrets.
Yes, upgrading to version 0.34.0.1 of Matrix Synapse fixes the vulnerability.